sk185169 - CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token

CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token

Please read this important update from Check Point.

Security Alert:

High

Product

Multi-Domain Security Management, Security Management

Version

R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10

Last Modified

2026-07-22

Symptoms

Mitigation

  1. Follow the Check Point Hardening Best Practices Guide.

  2. Limit Trusted Clients (GUI clients) to trusted IP addresses/subnets. To do so:

    1. In SmartConsole, go to Manage & Settings > Permissions & Administrators > Trusted Clients.
    2. Double-click the client you want to edit.
    3. In the Trusted Client configuration window that opens, change the settings as needed and ensure you do not use "Any" as a Type.
    4. Click OK.
  3. Protect Management access with Firewall, restrict access to trusted IP addresses, and verify that implied rules for control connections are enabled. This will create an implied rule that will prevent management access for non-authorized IP addresses.

How to Identify an Attack

  1. In SmartConsole, go to Logs & Monitor / Logs & Events, and search for events where either the source IP or destination IP matches one of the known attacker IP addresses.

Attacker IP addresses

SmartConsole query (src:151.241.99.207 OR dst:151.241.99.207 OR src:151.241.99.233 OR dst:151.241.99.233 OR src:158.62.198.182 OR dst:158.62.198.182 OR src:192.142.10.99 OR dst:192.142.10.99 OR src:139.28.37.250 OR dst:139.28.37.250)

  1. In SmartConsole, go to Logs & Monitor / Logs & Events > Audit Logs View and search for the query "Authentication method: application token":

Solution

This problem was fixed. The fix is included in:

Article Properties