Check Point flaw CVE-2026-16232 exploited in wild
ANSSI warns of actively exploited privilege escalation and security bypass vulnerabilities in Check Point Security Gateway and Management products.
The French cybersecurity agency ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in Check Point's Multi-Domain Security Management, Security Gateways, and Security Management products. The flaws affect versions R82, R82.10, and all releases prior to R81.20 that lack the latest security patches, and allow attackers to achieve privilege escalation and bypass security policy enforcement.
Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, elevating the urgency for affected organizations to apply patches. Two additional CVEs, CVE-2026-62144 and CVE-2026-62145, were also disclosed as part of the same set of advisories (sk185152, sk185153, sk185169) published July 22, 2026. Given Check Point's widespread deployment as perimeter security and management infrastructure, exploitation of these flaws could grant attackers significant control over network security policy and internal systems.
ANSSI recommends organizations consult the referenced Check Point security bulletins and apply the available patches without delay, particularly given the confirmed active exploitation of CVE-2026-16232.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0912
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free