A New Check Point Bug Hands Out Admin on the Console That Programs Every Firewall. It's the Second Auth-Bypass on KEV in Six Weeks.
- Patrick Duggan
- 15 minutes ago
- 4 min read
CISA added CVE-2026-16232 to the Known Exploited Vulnerabilities catalog on July 22. It is an improper-authentication flaw in Check Point SmartConsole, and the one-line version is the whole problem: an unauthenticated remote attacker can obtain an application login token and use it to log in with full administrative privileges. No password. No account. Admin.
The reason to care more about this than the average auth bypass is what SmartConsole is. It is not a gateway. It is the management client for Check Point's Security Management and Multi-Domain Management servers — the console administrators use to author the security policy and push it out to every enforcement point in the estate. A gateway bug owns one door. A management-plane bug owns the thing that decides what every door is allowed to do. Get administrative access there and you are not bypassing the firewall; you are rewriting the rules it enforces, quietly, for the whole fleet.
Second Check Point auth-bypass on KEV in six weeks
This is not an isolated entry. On June 8, CISA added CVE-2026-50751 — an improper-authentication flaw in the Check Point Security Gateway's IKEv1 key exchange that let an unauthenticated attacker establish a remote-access VPN connection without a valid password. We covered that one in "Four Edge Appliances, One Weekend," alongside the Palo Alto, SolarWinds Serv-U, and Oracle PeopleSoft flaws that were all being exploited the same weekend.
Six weeks later, the second one lands, and it is worse in kind: 50751 got an attacker a VPN session; 16232 gets them administrative control of the management console. Two authentication bypasses on the same vendor's KEV row in a month and a half is not a coincidence to note once. It is a pattern to plan around — the authentication surfaces on this product line are getting picked apart, and the attackers are moving up the stack from the gateway to the brain.
Qilin is already in this neighborhood
The timing matters because of who is working this terrain. The Qilin ransomware group has been observed targeting Check Point appliances, and Qilin's whole operating model right now is riding patched-or-freshly-disclosed edge-appliance auth bypasses into corporate networks. We wrote two days ago about Qilin doing exactly this through Palo Alto's GlobalProtect flaw, CVE-2026-0257 — a bug whose fix shipped in May while the ransomware kept walking through the ones nobody patched.
Put the two facts together. An unauthenticated path to full admin on the console that programs every Check Point firewall, and a ransomware crew that specializes in edge-appliance authentication bypasses and is already circling this vendor. That is not a hypothetical chain. That is the next incident report's first two paragraphs.
The defender playbook
Patch SmartConsole and the Management Server to the fixed build now. This is on the KEV list with an active-exploitation stamp, which means the federal remediation clock is already running and everyone else should treat it the same way.
Get the management plane off any untrusted network. SmartConsole talking to Security Management is administrative traffic. It has no business being reachable from the internet or from general user VLANs. If your Security Management server or SmartConsole access is exposed beyond a locked-down admin network, that exposure is the finding — fix it whether or not you have patched yet, because it is what turns a bug into a breach.
Hunt the management server, not just the gateways. The tell for this flaw is not on the firewalls — it is on the box that manages them. Audit for administrative logins to Security Management you cannot account for, especially from unfamiliar source addresses. Review recent policy installations and revisions: an attacker with admin does not need malware, they need one policy push that opens the paths they want. Look for new or modified administrator accounts. Any unexplained policy change in the exposure window should be treated as hostile until proven otherwise.
Assume the ransomware connection. Because Qilin is active against this product family, treat a suspected Check Point management compromise as a ransomware precursor, not a curiosity. That changes the urgency of the hunt and the value of your offline backups.
The point
The pattern under all of this is the one we keep writing because it keeps producing incidents: the dangerous flaw is rarely the exotic zero-day. It is an authentication bypass on the box that controls everything else, disclosed and patched on the vendor's schedule, exploited on the attacker's. Check Point now has two of those on the KEV list in six weeks, and the second one reaches the management console. Patch it, wall off the management plane, and hunt the Security Management server for logins and policy changes you cannot explain. The gateway was never the crown jewel. The console that programs the gateways is.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
