A critical authentication bypass vulnerability, identified as CVE-2026-16232, has been discovered in Check Point's SmartConsole, with a CVSS score of 9.3, and is being actively exploited by remote attackers. This flaw allows unauthenticated attackers to obtain a login token, granting them full administrative access to Security Management and Multi-Domain Management systems. Check Point has released security updates to address this vulnerability, along with other flaws. The exploitation of CVE-2026-16232 enables attackers to bypass authentication mechanisms, posing a significant threat to affected systems1. The active exploitation of this vulnerability expands the attack surface, making it essential for entities to prioritize patching based on their exposure and evidence of exploitation. This vulnerability's exploitation can have severe consequences, making it crucial for practitioners to take immediate action to secure their systems.
Check Point patches actively exploited SmartConsole authentication bypass flaw
⚠️ Critical Alert
Why This Matters
CVE-2026-16232 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- SecurityAffairs. (2026, July 23). Check Point patches actively exploited SmartConsole authentication bypass flaw. SecurityAffairs. https://securityaffairs.com/195848/hacking/check-point-patches-actively-exploited-smartconsole-authentication-bypass-flaw.html
Original Source
SecurityAffairs
Read original →