Skip to main content

Check Point Releases Security Update for Critical Authentication Bypass Vulnerability

CVE-2026-16232 could allow unauthenticated remote attackers to obtain full administrative access to exposed management servers.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-16232 could allow unauthenticated remote attackers to obtain full administrative access to exposed management servers.


Threat details

Exploitation of CVE-2026-16232

Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, and The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48558 to its Known Exploited Vulnerabilities (KEV) Catalog.

The NHS England National CSOC assesses further exploitation as likely.


Introduction

Check Point has released security updates to address a critical vulnerability in Check Point Security Management Server and Multi-Domain Security Management. Successful exploitation could allow an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges, enabling modification of security policies and configurations.

  • CVE-2026-16232 - "Improper Authentication" vulnerability - CVSSv3.1 score: 9.1

Remediation advice

Affected organisations are encouraged to review Check Point advisory sk185169, apply the relevant update as soon as possible, and implement the mitigation guidance within the advisory.


Definitive source of threat updates


Last edited: 23 July 2026 11:29 am