CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Check Point security advisory (AV26-735) – Update 1

criticalknown exploitedpublic exploitCVE-2026-16232
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-735 Date: July 22, 2026 Updated: July 23, 2026 On July 22, 2026, Check Point published a security advisory to address vulnerabilities in the following products. Included was a critical update for the following : Security Management, Multi-Domain Management – multiple versions Firewall, Multi-Domain Management, Multi-Domain Log Server – multiple versions Check Point is aware that CVE-2026-16232 is being exploited in the wild. Update 1 On July 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16232 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations. Security Advisory – Action Required – July 2026 Security Update Check Point Security CISA KEV: CVE-2026-16232

CSIRTS triage

What
A vulnerability allows exploitation in the wild.
Who is affected
Users of Check Point Security Management and Multi-Domain Management products.
Urgency
Remediation is urgent due to active exploitation.
Action
Review the provided web links and perform the suggested mitigations.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Security Management

Get an email when a new Security Management advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-07-23
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-735

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-16232coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security