
[CIVN-2026-0379] Authentication Bypass Vulnerability in Check Point Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Authentication Bypass Vulnerability in Check Point Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Check Point Quantum Security Management R82.10 with Jumbo Hotfix Take 36 or below
Check Point Quantum Security Management R82 with Jumbo Hotfix Take 118 or below
Check Point Quantum Security Management R81.20 with Jumbo Hotfix Take 158 or below
Check Point Quantum Security Management R81.10, R81, R80.30, R80.20, R80.10, R80 and R77.30
Check Point Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below
Check Point Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below
Check Point Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below
Check Point Multi-Domain Security Management R81.10, R81, R80.30, R80.20, R80.10, R80 and R77.30
Overview
An authentication bypass vulnerability has been reported in Check Point Quantum Security Management and Multi-Domain Security Management products, which could allow an unauthenticated remote attacker to obtain administrative access to the affected management server and modify security policies and configurations.
Target Audience:
All organizations and individuals using the affected Check Point products.
Risk Assessment:
Critical risk of unauthorized administrative access to the affected management server.
Impact Assessment:
Potential for authentication bypass, unauthorized administrative access, modification of security policies and security configurations, and compromise of the integrity and security of the affected management server.
Description
Check Point Quantum Security Management and Multi-Domain Security Management provide centralized management capabilities for Check Point security deployments.
An authentication bypass vulnerability exists in Check Point Quantum Security Management and Multi-Domain Security Management products due to improper authentication in the SmartConsole login process.
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to obtain an application login token and authenticate to the affected management server with full administrative privileges. The attacker may subsequently modify security policies and security configurations.
Solution
Apply appropriate security updates and mitigations as recommended by the vendor.
https://support.checkpoint.com/results/sk/sk185169/
Vendor Information
Check Point
https://support.checkpoint.com/results/sk/sk185169/
References
https://support.checkpoint.com/results/sk/sk185169/
CVE Name
CVE-2026-16232
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpqAXIACgkQ3jCgcSdc
ys+hxg/9HIsT7joJeWQ7EzvDaUTuzI6KdH+nmM4KuXiDJA9Y+TM2gDCnUQuMKdL9
BkPoGv1UHVV0Rj3Z1FsR89I0W1MSJR2YTWxBaZMLuYWB9nyJ8PNUX7Dr5ryU4W/b
eRBbYlPSkNLsQk5R3chh+tJ0bU+1lq2flGEL9z2reF+TZKmGEWjKoLspn86YTpYl
SNaZlqos9pKuKbvbAiAv5rb6lQOpzkw7zztx5ur74l62zHXGX6zlYFEhVutcad4i
AqTFuTC40lPRLPE8UVFigHPjYfPuaS2nfb77MvcX4hRD9fcX0LgrOAexSOOApoJG
Jqzd4nOqYGG8+j2HFpCYjz1ybPNB956A5JyMJQ5aG0gYm6fBpo9AlJOYZR70u1+R
zDYI0GQYRT0PiI5yktFLZXaiDPOsichIj4tPyk8MXpBrSk8LhCusk3QVIBZrcVx4
VRQDDAQfwpX/KQWMurtU8J+kkrNTv63u8Yueah4XxjRU3sazL3o/039vt6FQLusZ
nQIqx6d4tvsQ3OtJQ6iORJZFkX7nH7UFtPy0kuGoaojX3wTXEORP52q7xzmiHmx7
1u5eVDpp+RK4U53XMsHrkBNMijrOI+S1Mx/tjIw5gAoakYG54yWGk8MJNj8i5ZxB
pc18hCwf73toRm8YEGCMN0EHC4o2QeCyrqkZzOoPBFlXIAK6FUI=
=W3v8
—–END PGP SIGNATURE—–


