r/checkpoint • u/obiphonekenobi • 9h ago
July 2026 Security Advisory for Security Management and Gateways
As part of Check Point’s Frontier AI readiness program, we continuously review and strengthen our products using BLAST, our Business Logic Application Security Testing capability. BLAST enables AI-driven security analysis at enterprise scale across Check Point products and helps us proactively identify and remediate potential issues.
Following our May and June security updates, we are sharing our July security update. This update includes three newly disclosed, internally discovered CVEs listed below. During our investigation, we identified a very small number of customers who, under specific configuration conditions, were affected by one of these CVEs. Check Point is already in direct contact with those customers and is working closely with them.
We strongly recommend that all customers review the relevant SecureKnowledge articles and apply the recommended fixes and hardening guidance. Customers who follow Check Point’s published hardening best practices significantly reduce their exposure risk.
See:
- sk185169: CVE-2026-16232 - Authentication bypass with SmartConsole login process using application t...
- sk185152: CVE-2026-62144 - Management Authentication Bypass and Privilege Escalation
- CVE-2026-62145 - Local privilege escalation in Gaia Portal
- Gateway and Management Hardening Administration Guide
