2026-07-25 · view entry permalink →
Check Point Security Management: two more CVEs in the actively-exploited SmartConsole bundle — unauth management RCE (CVE-2026-62144) and Gaia Portal root escalation (CVE-2026-62145)
UPDATE · originally covered CVE-2026-16232 — Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1) (2026-07-23)
The prior entry covered the actively-exploited Check Point SmartConsole authentication bypass CVE-2026-16232. NCSC-NL advisory NCSC-2026-0264 (2026-07-24) and CERT-FR CERTFR-2026-AVI-0912 (2026-07-23) now confirm that the same Check Point patch release carried two further CVEs on the same attack surface that had not been surfaced individually (NCSC-NL, 2026-07-24; CERT-FR, 2026-07-23).
CVE-2026-62144 (NCSC-NL CVSS v4 10.0; Check Point publishes only a qualitative "High" severity, no numeric CVSS 3.1 score) lets an unauthenticated network attacker "run any command on the Management including run-script and exec-command on Security Gateway" — i.e. arbitrary command execution against a Security Management or Multi-Domain Security Management server, and by extension against every gateway that server manages, whenever the Management is reachable without firewall protection or with an unrestricted Trusted Clients (GUI clients) list (Check Point PSIRT sk185152, 2026-07-22). CVE-2026-62145 (Check Point CNA CVSS 3.1 7.5; NCSC-NL CVSS v4 9.4) is a Gaia Portal escalation in which "an authenticated attacker with read-only access [can] run commands as root," affecting Security Gateways and Security Management alike (Spark Gateways excepted) (Check Point PSIRT sk185153, 2026-07-22). Both span the same version range as the exploited CVE-2026-16232 (R77.30 through R81.20/R82/R82.10 prior to fix) and both close with the same Jumbo Hotfix Accumulator line.
The material delta for defenders is exposure, not new exploitation: Check Point reports only CVE-2026-16232 seen abused, against a small number of customers who left the Management internet-exposed with a permissive Trusted Clients configuration (NCSC-NL, 2026-07-24).
An unauthenticated attacker can run any command on the Management including run-script and exec-command on Security Gateway.
A vulnerability in Gaia Portal allows an authenticated attacker with read-only access to run commands as root.