CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3094

As cited

Copy frozen at (site build).

vulnerabilities

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers are actively exploiting CVE-2026-16232, a critical authentication bypass in Check Point Security Management and Multi-Domain Security Management servers. An unauthenticated attacker can obtain an application login token to gain full admin privileges via SmartConsole and modify security policies and configurations. Check Point confirmed the vulnerability is under active exploitation by a limited number of threat actors.

Why it matters: Organizations running Check Point management servers face immediate risk of firewall policy manipulation and potential network compromise; apply the vendor patch without delay.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers are actively exploiting CVE-2026-16232, a critical authentication bypass in Check Point Security Management and Multi-Domain Security Management servers. An unauthenticated attacker can obtain an application login token to gain full admin privileges via SmartConsole and modify security policies and configurations. Check Point confirmed the vulnerability is under active exploitation by a limited number of threat actors.

Why it matters: Organizations running Check Point management servers face immediate risk of firewall policy manipulation and potential network compromise; apply the vendor patch without delay.

VendorsCheck Point
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary