Check Point hole grants unauthenticated attackers full SmartConsole admin privileges

Tags:

Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3.

In its security alert, Check Point described the bug as one allowing an unauthenticated attacker to “obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration.”

The company has released a patch for the bug and also recommends that users “limit Trusted Clients, GUI clients, to trusted IP addresses/subnets.” That approach has always been a best practice, but practical networking realities today make it challenging to maintain. Check Point said that the exploit has impacted ten of its customers, all of whom it had notified directly.

Far worse than most

Frank Dickson, group VP for security at IDC, said this security hole is far worse than most.

“This hits harder than your average CVE because of where it lives,” he said. “The CVE targets the SmartConsole login on Check Point’s Security Management Server, the console that pushes policy to every gateway underneath it. Popping a gateway gets you one lock picked. Popping the management server is more like finding the One Ring: one stolen token to rule every gateway it manages, no need to fight each one individually. The attacker can rewrite policy, open new VPN paths and kill the logging.”

In an interview with CSO Online, Lotem Finkelstein, vice president of research at Check Point, said that the company learned of the vulnerability on Sunday, emailed customers the same day, and released the patch within 72 hours.

But when his team re-reviewed earlier logs, knowing what to look for, they spotted this hole being attacked as early as April, Finkelstein said.

The fact that, over the course of three months, the team only found ten organizations under attack, indicated that it has been very difficult for the attacker to find vulnerable systems, he noted; customers were, in the main, using secure settings to protect themselves.

Nonetheless, Finkelstein said, Check Point considers this hole to be “a severe vulnerability.”

Challenges of IP address restrictions

While it can be technically challenging to keep the IP address allowlists that Check Point recommends current, given DHCP’s ability to easily change those addresses, Assaf Morag, a cybersecurity researcher at Flare, noted that specifically limiting access to a management console is far more critical than limiting overall external access.

“Implementing Trusted Clients as a per-IP allowlist is impractical,” he said, but that is not the case with restricting management access. “The more scalable solution is to restrict access based on trusted administrative network segments such as VPN pools, management VLANs, or jump hosts rather than maintaining lists of individual DHCP-assigned client addresses,” he explained. “That gives you the security benefit without creating a full-time administrative task. Maintaining allowlists for individual hosts is much more practical when those hosts have stable, predictable IP addresses, rather than dynamically assigned DHCP addresses.”

Pieter Arntz, malware intelligence researcher at Malwarebytes, also noted that the constantly changing nature of global IP addresses can prove annoying to IT teams. Stressing that he is not familiar with Check Point’s specific settings, he noted, “Certain settings are a nuisance when applied strictly, and at some point the IT staff gets tired of constantly tweaking and they abandon the most secure path.”

Ideal platform for long-term attacks

Mike Wilkes, enterprise CISO at Aikido Security,  agreed that the severity and exposure of this hole is alarming.

“This is exactly the kind of vulnerability that keeps CISOs awake at night because it strikes at the one system that is supposed to stand between the attacker and everything else. An authentication bypass that grants administrative control of a perimeter firewall isn’t just another CVE to patch. It’s an invitation for an adversary to rewrite the rules of the network itself,” he said. “The uncomfortable reality is that nobody runs a CrowdStrike agent on their firewall. Once an attacker owns an edge device, they gain a uniquely privileged position that often falls outside the visibility of traditional endpoint security, making it an ideal platform for persistence, credential theft, traffic manipulation, and long-term espionage.”

IDC’s Dickson strongly encouraged CISOs to deploy the patch, not to just change settings to mitigate the issue. 

“Apply the actual hotfix,” he said. “Don’t just restrict Trusted Client IPs and call it done. That’s a stopgap, not a fix. Any internet-facing management console, Check Point or otherwise, is a five-alarm architecture problem independent of this CVE.”

And, he added, “since attackers here can disable logging, audit admin activity going back before the bug surfaced. Quiet logs aren’t proof nothing happened. This is the recurring theme with ‘single pane of glass’ security tools: the console built to make everything easier to run is also the one thing you really don’t want someone else driving.”

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *