CHECK Point has issued security updates to address a critical authentication bypass vulnerability (CVE-2026-16232) in SmartConsole, which is currently under active exploitation. This flaw allows unauthenticated remote attackers to gain full administrative access by obtaining a login token. Check Point has reported a small number of affected customers and recommended restricting access to trusted IP addresses. The vulnerability affects several product versions of Security Management Server.
Other vulnerabilities (CVE-2026-62144 and CVE-2026-62145) have also been patched, with CVSS scores indicating their severity. Users are advised to apply the July 22 Jumbo hotfix and implement firewall protections.