A critical vulnerability, CVE-2026-16232, allows unauthenticated attackers to bypass authentication in Check Point's SmartConsole, gaining full administrator access. The flaw, which has a CVSS score of 9.1, affects several versions of the Check Point Quantum Security Management product and is actively exploited in the wild. Attackers exploit a broken trust boundary in the login process, leading to unauthorized admin access.
Check Point has released patches for certain versions, and users are advised to restrict access to management servers and monitor audit logs for suspicious activity.