ON 22 July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2026‑16232 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Check Point SmartConsole and is named the Check Point SmartConsole Improper Authentication Vulnerability. It allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVE‑2026‑16232 is an improper authentication flaw in the SmartConsole web interface. Exploitation does not require any credentials; an attacker can send a crafted request to retrieve a valid session token and then use that token to log in as an administrator. The vulnerability carries a CVSS v3.1 base score of 9.1, rating it as critical. No patch or advisory has been published by Check Point at the time of writing, so the patch status is unknown.
Because the entry appears in the KEV catalogue, CISA confirms that active exploitation of CVE‑2026‑16232 has been observed in the wild. There is no publicly known link to ransomware campaigns at this stage. Federal Civilian Executive Branch (FCEB) agencies must apply the required mitigations by 25 July 2026, which is the remediation deadline set by CISA for this vulnerability.
CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines.
Although the directive primarily binds FCEB agencies, all organisations should review their exposure to Check Point SmartConsole and apply any available mitigations promptly.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-16232 and the CISA KEV catalogue.