Check Point Releases Security Update for Critical Authentication Bypass Vulnerability
CVE-2026-16232 could allow unauthenticated remote attackers to obtain full administrative access to exposed management servers.
Summary
CVE-2026-16232 could allow unauthenticated remote attackers to obtain full administrative access to exposed management servers.
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-16232
Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, and The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48558 to its Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses further exploitation as likely.
Introduction
Check Point has released security updates to address a critical vulnerability in Check Point Security Management Server and Multi-Domain Security Management. Successful exploitation could allow an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges, enabling modification of security policies and configurations.
- CVE-2026-16232 - "Improper Authentication" vulnerability - CVSSv3.1 score: 9.1
Remediation advice
Affected organisations are encouraged to review Check Point advisory sk185169, apply the relevant update as soon as possible, and implement the mitigation guidance within the advisory.
Definitive source of threat updates
Last edited: 23 July 2026 11:29 am