Hackers Are Actively Exploiting a Flaw in Check Point Security Software

A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

ThreatVectr Newsdesk· 3 min read
A server rack in a dimly lit data center, glowing amber and blue indicator lights reflecting off brushed-metal chassis surfaces, shallow depth of field on the f
Share

Key points

  • CVE-2026-16232 is an actively exploited flaw in Check Point Security Management and Multi-Domain Management software that lets attackers gain full administrator access without a password.
  • Check Point confirmed a limited number of customers with internet-facing management systems were hit before a patch was released.
  • The U.S. government's cybersecurity watchdog, CISA, added the flaw to its official danger list on Wednesday and ordered federal agencies to fix it by 25 July.
  • The Qilin ransomware group, criminals who lock companies out of their own files and demand payment, was recently seen targeting Check Point systems.
  • Two additional flaws, CVE-2026-62144 and CVE-2026-62145, were patched at the same time, though neither has been exploited in the wild.

Check Point sells software that companies use to manage the firewalls and security rules protecting their networks. Think of it as a control room for a building's entire alarm system. This week, the company confirmed that criminals found and used a secret back door into that control room before anyone knew it existed.

What exactly went wrong?

The flaw, tracked as CVE-2026-16232, is an authentication bypass, meaning the software can be tricked into handing out an administrator login token without first checking whether the person asking is actually allowed in. Once a criminal had that token, they could walk straight into Check Point's SmartConsole management interface with full admin rights, rewrite security rules, and effectively turn off the digital locks protecting the organisation.

Check Point found this vulnerability internally. The problem: when they looked closer, the flaw had already been used against real customers.

Vulnerability Severity Products affected Exploited in the wild
CVE-2026-16232 Critical Security Management, Multi-Domain Management Yes
CVE-2026-62144 Critical Security Management, Multi-Domain Management No
CVE-2026-62145 High Firewall, Multi-Domain Management, Multi-Domain Log Server No

Should customers be worried?

If your organisation uses Check Point management products and they are directly reachable from the open internet with no restrictions on who can connect, yes. That is precisely the configuration attackers targeted.

Check Point says only a limited number of customers were hit, and those organisations have been privately notified. Patches and mitigations are available now. The company also released indicators of compromise, which are digital fingerprints of the attack that security teams can search for in their own logs to check whether they were targeted.

This is the third Check Point flaw to land on CISA's Known Exploited Vulnerabilities list. CVE-2026-50751 was used in attacks in May. CVE-2024-24919 was exploited through 2024. The pattern is worth noting: Check Point management interfaces keep appearing in real attack chains.

What about the ransomware angle?

No group has been formally identified as responsible for the CVE-2026-16232 attacks. The Qilin ransomware gang, criminals who specialise in breaking into networks and encrypting, or scrambling, files until a ransom is paid, has recently been observed probing Check Point appliances. Whether Qilin is behind these specific intrusions is not yet confirmed, as first reported by SecurityWeek.

For ordinary people whose employers or service providers use Check Point tools: the immediate risk is that an attacker who controls a company's security management system can quietly disable defences, making follow-on attacks much easier. Watch for any unusual communications from companies you do business with about security incidents in the coming weeks.

The operational takeaway: management interfaces should never be exposed to the raw internet with no IP allowlist. That one config choice is the difference between a patch being an inconvenience and a breach being inevitable.

© 2026 Threat Vectr