[CIVN-2026-0379] Authentication Bypass Vulnerability in Check Point Products

By Published On: July 29, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Authentication Bypass Vulnerability in Check Point Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Check Point Quantum Security Management R82.10 with Jumbo Hotfix Take 36 or below

Check Point Quantum Security Management R82 with Jumbo Hotfix Take 118 or below

Check Point Quantum Security Management R81.20 with Jumbo Hotfix Take 158 or below

Check Point Quantum Security Management R81.10, R81, R80.30, R80.20, R80.10, R80 and R77.30

Check Point Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below

Check Point Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below

Check Point Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below

Check Point Multi-Domain Security Management R81.10, R81, R80.30, R80.20, R80.10, R80 and R77.30

Overview


An authentication bypass vulnerability has been reported in Check Point Quantum Security Management and Multi-Domain Security Management products, which could allow an unauthenticated remote attacker to obtain administrative access to the affected management server and modify security policies and configurations.


Target Audience:

All organizations and individuals using the affected Check Point products.


Risk Assessment:

Critical risk of unauthorized administrative access to the affected management server.


Impact Assessment:

Potential for authentication bypass, unauthorized administrative access, modification of security policies and security configurations, and compromise of the integrity and security of the affected management server.


Description


Check Point Quantum Security Management and Multi-Domain Security Management provide centralized management capabilities for Check Point security deployments.


An authentication bypass vulnerability exists in Check Point Quantum Security Management and Multi-Domain Security Management products due to improper authentication in the SmartConsole login process.


Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to obtain an application login token and authenticate to the affected management server with full administrative privileges. The attacker may subsequently modify security policies and security configurations.


Solution


Apply appropriate security updates and mitigations as recommended by the vendor.

https://support.checkpoint.com/results/sk/sk185169/



Vendor Information


Check Point

https://support.checkpoint.com/results/sk/sk185169/


References


 

https://support.checkpoint.com/results/sk/sk185169/


CVE Name

CVE-2026-16232




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpqAXIACgkQ3jCgcSdc

ys+hxg/9HIsT7joJeWQ7EzvDaUTuzI6KdH+nmM4KuXiDJA9Y+TM2gDCnUQuMKdL9

BkPoGv1UHVV0Rj3Z1FsR89I0W1MSJR2YTWxBaZMLuYWB9nyJ8PNUX7Dr5ryU4W/b

eRBbYlPSkNLsQk5R3chh+tJ0bU+1lq2flGEL9z2reF+TZKmGEWjKoLspn86YTpYl

SNaZlqos9pKuKbvbAiAv5rb6lQOpzkw7zztx5ur74l62zHXGX6zlYFEhVutcad4i

AqTFuTC40lPRLPE8UVFigHPjYfPuaS2nfb77MvcX4hRD9fcX0LgrOAexSOOApoJG

Jqzd4nOqYGG8+j2HFpCYjz1ybPNB956A5JyMJQ5aG0gYm6fBpo9AlJOYZR70u1+R

zDYI0GQYRT0PiI5yktFLZXaiDPOsichIj4tPyk8MXpBrSk8LhCusk3QVIBZrcVx4

VRQDDAQfwpX/KQWMurtU8J+kkrNTv63u8Yueah4XxjRU3sazL3o/039vt6FQLusZ

nQIqx6d4tvsQ3OtJQ6iORJZFkX7nH7UFtPy0kuGoaojX3wTXEORP52q7xzmiHmx7

1u5eVDpp+RK4U53XMsHrkBNMijrOI+S1Mx/tjIw5gAoakYG54yWGk8MJNj8i5ZxB

pc18hCwf73toRm8YEGCMN0EHC4o2QeCyrqkZzOoPBFlXIAK6FUI=

=W3v8

—–END PGP SIGNATURE—–

Share this article