All incidents

CISA adds four exploited flaws to Known Exploited Vulnerabilities catalog

vulnerabilityopenJun 8, 2026 — Aug 19, 2026
Check Point SmartConsole authentication bypass flaw (CVE-2026-16232) exploited in the wild

CHECK Point’s SmartConsole authentication bypass flaw, tracked as CVE-2026-16232, is being actively exploited in the wild, allowing attackers to gain administrative access without valid credentials. Fortinet researchers observed the flaw in use during ongoing malware distribution campaigns.

The vulnerability affects SmartConsole releases prior to version R81.10, where a specially crafted HTTP request can bypass the authentication check and execute arbitrary commands on the managed security gateway. CISA’s advisory notes the flaw carries a CVSS v3.1 base score of 9.1, reflecting its potential for full device control. Check Point released a hotfix in June 2026 that restores proper validation of login tokens.

The flaw was added to CISA’s Known Exploited Vulnerabilities catalogue after detection of active exploitation beginning in early June 2026, with activity persisting through mid‑August. CISA’s KEV entry for another critical flaw illustrates how the agency tracks such threats, though no specific threat actor has been linked to the SmartConsole issue. Attackers have used the bypass to push malicious configurations and install backdoors on perimeter devices.

Administrators should first verify the exact build of SmartConsole in use and apply the latest hotfix from Check Point’s support portal without delay. SecurityOnline’s report highlights that organisations exposing the console to untrusted networks are at greatest risk. Restricting console access to authorised management subnets and enforcing multi‑factor authentication wherever feasible reduces the chance of successful abuse. Continuous review of authentication logs for unexpected login attempts or unexplained configuration changes can help spot ongoing attacks.

Network segmentation that isolates the management plane from user traffic limits the ability of an attacker to pivot after exploiting the bypass. Keeping associated firmware and related security blades up to date also lowers the chance of chaining this bug with other vulnerabilities. Prompt patching remains the most effective defence against the active exploitation of CVE-2026-16232.

Intelligence briefing updated Aug 19, 2026

CVE-2026-56162 10.0 CVE-2026-63508 10.0 CVE-2026-65667 10.0 CVE-2026-0770 9.8 KEV CVE-2026-33824 9.8 KEV CVE-2026-50522 9.8 KEV CVE-2026-58644 9.8 KEV CVE-2026-59309 9.8 CVE-2026-59310 9.8 KEV CVE-2026-63030 9.8 KEV CVE-2026-65400 9.8 KEV CVE-2026-16232 9.1 KEV CVE-2026-55040 9.1 KEV CVE-2026-60137 9.1 KEV CVE-2026-45659 8.8 KEV CVE-2021-27137 8.1 KEV CVE-2026-63520 8.1 CVE-2026-56164 5.3 KEV CVE-2026-41703 CVE-2026-41709 CVE-2026-47876 CVE-2026-65040
Root sourcewww.fortinet.com
Timeline Coverage

Swipe to explore timeline