CVE-2026-16232
Check Point SmartConsole Improper Authentication Vulnerability
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Deadline for federal agencies: 2026-07-25.
12 articles across 6 outlets · first covered Jul 22, 2026 · latest Jul 29, 2026
Associated threat actors
Coverage timeline
-
Check Point SmartConsole Authentication Bypass CVE-2026-16232 Exploited as Zero-Day, PoC and Details Publicsecurityonline.info · Jul 29, 2026
-
UK firms must patch now as CISA flags six active exploitssecurityonline.info · Jul 27, 2026
-
Heap overflow bug in Knot Resolver lets attackers run codesecurityonline.info · Jul 24, 2026
-
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalogsecurityaffairs.com · Jul 23, 2026
-
CVE-2026-16232 flaw lets hackers access Check Point adminwww.rapid7.com · Jul 23, 2026
-
Check Point fixes critical SmartConsole auth bypass exploited nowsecurityaffairs.com · Jul 23, 2026
-
Check Point Zero Day CVE-2026-16232 Exploited for Auth Bypasswww.securityweek.com · Jul 23, 2026
-
Two Active BIND Exploits Highlighted as Nine Flaws Patchedsecurityonline.info · Jul 23, 2026
-
GitHub Actions Abused to Steal Credentials from PHP Packagessecurityonline.info · Jul 23, 2026
-
CISA flags Check Point SmartConsole flaw in latest KEV updatewww.cisa.gov · Jul 22, 2026
-
CISA Flags Active Exploitation of Check Point SmartConsole Flawcisa.gov · Jul 22, 2026
-
Check Point SmartConsole flaw CVE-2026-16232 under active attacksecurityonline.info · Jul 22, 2026