CVE-2026-16232
published 2026-07-22CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-25
Exploited in the wild
EPSS
72.05%
99.4th percentile
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Affected
130 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.1CRITICAL
cisa9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Check Point Quantum Security Management up to R81.10 SmartConsole Login improper authentication (EUVD-2026-47700)
vuldb·2026-07-22·CVSS 9.1
CVE-2026-16232 [CRITICAL] Check Point Quantum Security Management up to R81.10 SmartConsole Login improper authentication (EUVD-2026-47700)
A vulnerability was found in Check Point Quantum Security Management and Multi-Domain Security Management up to R81.10 and classified as very critical. The affected element is an unknown function of the component SmartConsole Login. The manipulation results in improper authentication.
This vulnerability is cataloged as CVE-2026-16232. The attack may be launched remotely. Furthermore, there is an exploit available.
GHSA
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full
ghsa_unreviewed·2026-07-22
CVE-2026-16232 [CRITICAL] CWE-287 An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
VulnCheck
Check Point SmartConsole Improper Authentication Vulnerability
vulncheck·2026·CVSS 9.1
CVE-2026-16232 [CRITICAL] CWE-287 Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Affected: Check Point SmartConsole
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherenc
CISA
Check Point SmartConsole Improper Authentication Vulnerability
cisa·2026-07-22·CVSS 9.1
CVE-2026-16232 [CRITICAL] CWE-287 Check Point SmartConsole Improper Authentication Vulnerability
Vulnerability: Check Point SmartConsole Improper Authentication Vulnerability
Affected: Check Point SmartConsole
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ens
No detection rules found.
Nuclei
Check Point Security Management Server - SmartConsole Authentication Bypass
nuclei·CVSS 9.1
CVE-2026-16232 [CRITICAL] Check Point Security Management Server - SmartConsole Authentication Bypass
Check Point Security Management Server - SmartConsole Authentication Bypass
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Template:
id: CVE-2026-16232
info:
name: Check Point Security Management Server - SmartConsole Authentication Bypass
author: sfewer-r7,
Metasploit
Check Point SmartConsole Authentication Bypass Run Script RCE
metasploit·CVSS 9.8
CVE-2026-16232 [CRITICAL] Check Point SmartConsole Authentication Bypass Run Script RCE
Check Point SmartConsole Authentication Bypass Run Script RCE
This module exploits CVE-2026-16232, an authentication bypass in the Check Point SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server. A vulnerable management server accepts a client-supplied SIC distinguished name during an application certificate bind instead of binding the application identity to the authenticated peer certificate. The module uses the unauthenticated FWM/CPMI service to replay the management server's own SIC DN, mints a SmartConsole SSO ticket, and redeems it over the CPM SOAP service. The resulting administrative session is then used to submit a local one-time run-script command. Affected versions include R82.10 before Jumbo Hotfix Take 36, R82 before J
Hackernews
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
blogs_hackernews·2026-07-29·CVSS 9.1
CVE-2026-16232 [CRITICAL] Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
"By lever
Rapid7
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
blogs_rapid7·2026-07-28·CVSS 9.1
CVE-2026-16232 [CRITICAL] Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
## Overview
On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure.
Our analysis finds th
Checkpoint
27th July – Threat Intelligence Report
blogs_checkpoint·2026-07-27
CVE-2026-16232 27th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stol
Hackernews
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
blogs_hackernews·2026-07-27
CVE-2026-16232 ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up.
This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.
That is the mood. Here is the full recap.
## ⚡ Threat of the Week
OpenAI Says Its AI Agent Went Rogue and Targeted Hugging Face - OpenAI disclosed that it lost control of two AI models during a security evaluation that ended in a breach o
Rapid7
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
blogs_rapid7·2026-07-23·CVSS 9.1
CVE-2026-16232 [CRITICAL] CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
## Overview
On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process classified as improper authentication ( CWE-287 ). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.
Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote
Hackernews
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
blogs_hackernews·2026-07-23·CVSS 9.1
CVE-2026-16232 [CRITICAL] Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild .
The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
"Successful exploitation allow
2026-07-22
Published
2026-07-22
Added to CISA KEV
Exploited in the wild