CHECK Point has discovered a critical zero-day vulnerability (CVE-2026-16232) in its Security Management and Multi-Domain Management products, which has been exploited in the wild. This vulnerability allows attackers to bypass authentication and gain administrator access through an application login token. Patches and mitigations have been released, and affected customers have been notified. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating action by federal agencies.
This incident marks Check Point's third entry in the CISA catalog in 2026, following two other vulnerabilities earlier in the year. The Qilin ransomware group has been linked to these attacks.