{
  "name": "Security Advisory - Action Required - July 2026 Security Update",
  "slug": "security-advisory-action-required-july-2026-security-update",
  "description": "A security update addresses multiple vulnerabilities discovered during routine security review, including authentication bypass issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address authentication bypass with privilege escalation and local privilege escalation in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices.",
  "published": "2026-07-24T14:24:56.259000+00:00",
  "created_at": "2026-07-24T14:52:16.774000+00:00",
  "modified_at": null,
  "created_at_opencti": "2026-07-24T14:52:16.774000+00:00",
  "author": "AlienVault",
  "confidence": 100,
  "report_types": [
    "threat-report"
  ],
  "labels": [
    "active exploitation",
    "authentication bypass",
    "cve-2026-16232",
    "cve-2026-62144",
    "cve-2026-62145",
    "firewall",
    "gaiaos",
    "management products",
    "privilege escalation",
    "smartconsole"
  ],
  "tags": [],
  "related_entities": {
    "vulnerabilities": [
      {
        "id": "2a025f82-2a50-44fb-b023-c9dcb1501ac8",
        "name": "CVE-2026-62145"
      },
      {
        "id": "ad8c78dd-b7c5-4e88-891e-5055d916c195",
        "name": "CVE-2026-62144"
      },
      {
        "id": "7e6d39ee-cdb3-42ab-a00d-93541c043cd5",
        "name": "CVE-2026-50751"
      },
      {
        "id": "001d04de-5232-4eed-836f-bd6f711378d0",
        "name": "CVE-2026-16232"
      }
    ],
    "indicators": [
      {
        "id": "3e8691cf-79c6-40d6-a19f-c03421350fb3",
        "name": "151.241.99.233"
      },
      {
        "id": "4dd10791-e032-4ba8-ad1a-07f2aacf63aa",
        "name": "139.28.37.250"
      },
      {
        "id": "4959643d-0ffb-4468-95b1-75f923b3f8cb",
        "name": "158.62.198.182"
      },
      {
        "id": "2185f357-89c2-43fc-a4b9-260b3022cf8c",
        "name": "151.241.99.207"
      }
    ],
    "attack_patterns": [
      {
        "id": "9f11a241-9abc-4c57-95dd-33955ab08826",
        "name": "T1078"
      },
      {
        "id": "1f2ce0cc-430c-4317-a332-83a27cbad1d3",
        "name": "T1548"
      },
      {
        "id": "a8893562-3ab3-4071-914c-2cc4649cb2d3",
        "name": "T1548.001"
      },
      {
        "id": "6b7df637-ffba-4104-b70e-5bd05637d0f6",
        "name": "T1212"
      },
      {
        "id": "64cdebc9-0fb4-48f2-bf4f-b87f3741f664",
        "name": "T1068"
      },
      {
        "id": "894026fa-e537-4b95-b612-7dd8bc367a0d",
        "name": "T1078.001"
      },
      {
        "id": "fcd96dc0-500e-4354-bd97-5c65718a9004",
        "name": "T1562"
      },
      {
        "id": "6c8f8a40-2746-4a37-86bd-81e82afa6e62",
        "name": "T1190"
      },
      {
        "id": "b9eab970-53dd-4977-9a26-c4fe566e422d",
        "name": "T1133"
      },
      {
        "id": "fc699aef-8931-4a79-8f79-9651be9abd50",
        "name": "T1021"
      },
      {
        "id": "7364ca96-72bf-4b7f-afef-ce2583b1ed58",
        "name": "T1562.001"
      },
      {
        "id": "195d9773-4de3-4f61-b94d-a2b53cb65608",
        "name": "T1021.001"
      }
    ],
    "observables": [
      {
        "id": "b548175a-8a92-428a-a754-950e94d14a2c",
        "name": "151.241.99.207"
      },
      {
        "id": "ebb976f4-3b39-411d-84e8-85fd8e3c5d8c",
        "name": "158.62.198.182"
      },
      {
        "id": "3d78aee0-284a-4ec8-a7f8-42956c72cc00",
        "name": "151.241.99.233"
      },
      {
        "id": "88e70228-4ff2-4890-b906-83b3350f8ced",
        "name": "139.28.37.250"
      }
    ]
  },
  "external_refs": [
    {
      "id": "cb8ca37e-87d8-4a8c-89ec-902a715b3100",
      "standard_id": "external-reference--9a71b152-a045-5531-9307-ea43e5a79c92",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://otx.alienvault.com/pulse/6a6375b8843a154abdf4a0f0",
      "hash": null,
      "external_id": "6a6375b8843a154abdf4a0f0",
      "created": "2026-07-24T14:52:16.678Z",
      "modified": "2026-07-24T14:52:16.678Z",
      "createdById": null
    },
    {
      "id": "1921eceb-d06b-4a28-ab65-0f590f4a78d1",
      "standard_id": "external-reference--b2d8f6c0-bb53-51ee-9ae1-2b19a1273276",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/",
      "hash": null,
      "external_id": null,
      "created": "2026-07-24T14:52:16.708Z",
      "modified": "2026-07-24T14:52:16.708Z",
      "createdById": null
    }
  ]
}