New Check Point Zero-Day Vulnerability Exploited in the Wild
Check Point has notified customers that a critical zero-day vulnerability discovered recently in its products has been exploited in the wild.
The exploited vulnerability is tracked as CVE-2026-16232 and it affects the cybersecurity company’s Security Management and Multi-Domain Management products.
The flaw has been described as an authentication bypass issue that allows an attacker to obtain an application login token. The token can then be used to log in via the SmartConsole with full administrator privileges, and make changes to the security policy and configuration.
“Check Point confirmed that this vulnerability has been observed in the wild, affecting a limited number of customers whose Management environments were directly exposed to the Internet without IP restrictions,” Check Point said.
The security firm has released patches and mitigations, and made available indicators of compromise (IoCs) for the attacks exploiting CVE-2026-16232. Targeted customers have been privately notified.
CISA added CVE-2026-16232to its...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE