All incidents

Check Point SmartConsole authentication bypass (CVE-2026-16232) under active exploitation

vulnerabilityopenJul 22, 2026 — Jul 22, 2026
CISA Flags Active Exploitation of Check Point SmartConsole Flaw

ON 22 July 2026 the Cybersecurity and Infrastructure Security Agency added CVE‑2026‑16232 to its Known Exploited Vulnerabilities catalogue after confirming active exploitation of a flaw in Check Point SmartConsole. The vulnerability lets an unauthenticated remote attacker obtain an application login token and use it to gain full administrative privileges. Organisations with the management console exposed to the internet are at immediate risk.

Tracked as CVE‑2026‑16232, the flaw carries a CVSS v3.1 base score of 9.1, rating it critical. It stems from improper authentication in the SmartConsole web interface where a specially crafted request returns a valid session token. An attacker can then present that token to the login portal and authenticate as an administrator without needing any credentials.

Check Point released a jumbo hotfix on 22 July 2026 that addresses CVE‑2026‑16232 along with two related vulnerabilities, details of which can be seen in the vendor’s advisory here. Versions of SmartConsole prior to this update are affected, particularly those configured to accept connections from untrusted networks. The agency’s KEV entry notes that exploitation has been observed in the wild.

Although no specific threat actor has been linked to the attacks, CISA’s inclusion in the KEV catalogue signals that the flaw is being actively used. Security researchers reported four distinct exploitation attempts today, as outlined in their analysis here, highlighting the speed with which adversaries are moving. Check Point advises organisations to apply the hotfix and to enforce network‑level controls pending patching.

Defenders should prioritize installing the jumbo hotfix from Check Point’s support portal. Where immediate patching is not feasible, administrators must restrict SmartConsole access to known IP addresses using firewalls or VPNs and disable direct internet exposure. Logging of authentication requests should be reviewed for anomalies such as repeated token‑generation attempts from unfamiliar sources.

In the longer term, organisations should audit all management interfaces for unnecessary web exposure and enforce multi‑factor authentication on privileged accounts. Regular vulnerability scanning and subscription to CISA’s KEV feed will help detect similar issues early. Staying current with vendor advisories remains a key part of defence.

Intelligence briefing updated Jul 22, 2026

CVE-2026-16232 9.1 KEV
Root sourcenvd.nist.gov
Timeline Coverage

Swipe to explore timeline