Verify Level has notified clients {that a} crucial zero-day vulnerability found not too long ago in its merchandise has been exploited within the wild.
The exploited vulnerability is tracked as CVE-2026-16232 and it impacts the cybersecurity firm’s Safety Administration and Multi-Area Administration merchandise.
The flaw has been described as an authentication bypass difficulty that enables an attacker to acquire an utility login token. The token can then be used to log in through the SmartConsole with full administrator privileges, and make adjustments to the safety coverage and configuration.
“Verify Level confirmed that this vulnerability has been noticed within the wild, affecting a restricted variety of clients whose Administration environments had been immediately uncovered to the Web with out IP restrictions,” Verify Level mentioned.
The safety agency has launched patches and mitigations, and made out there indicators of compromise (IoCs) for the assaults exploiting CVE-2026-16232. Focused clients have been privately notified.
CISA added CVE-2026-16232 to its Recognized Exploited Vulnerabilities (KEV) catalog on Wednesday, instructing federal companies to handle it by July 25.
That is the third Verify Level vulnerability added to CISA’s KEV listing, after CVE-2026-50751, which attackers exploited as a zero-day in Could, and CVE-2024-24919, which risk actors leveraged in 2024.
Along with CVE-2026-16232, Verify Level’s newest updates patch CVE-2026-62144, a crucial authentication bypass and privilege escalation flaw affecting Safety Administration and Multi-Area Administration, and CVE-2026-62145, a high-severity native privilege escalation affecting Firewall, Multi-Area Administration, and Multi-Area Log Server merchandise.
All three vulnerabilities had been found internally by Verify Level, however an evaluation revealed that CVE-2026-16232 had already been exploited as a zero-day.
It’s unclear who’s behind the most recent assaults, however the Qilin ransomware group was not too long ago noticed concentrating on Verify Level home equipment.
Associated: Fourth SharePoint Vulnerability Exploited in Previous Month’s Wave of Assaults
Associated: Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
Associated: SonicWall Zero-Days Exploited to Ship Customized Malware for Weeks Earlier than Patch








