216.73.216.145

Security Advisory - Action Required - July 2026 Security Update

· Published 24/07/2026 16:24

Export JSON

Essential information

Published
24/07/2026 16:24
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
active exploitation authentication bypass cve-2026-16232 cve-2026-62144 cve-2026-62145 firewall gaiaos management products privilege escalation smartconsole
Related entities
4 vulnerabilities (cve), 4 indicators, 4 observables, 12 techniques (mitre)

Description

A security update addresses multiple vulnerabilities discovered during routine security review, including issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address with and local in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices.

External references