CVE-2026-16232
published 2026-07-22CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login…
PriorityP194critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-07-25
Exploited in the wild
EPSS
12.68%
95.8th percentile
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Affected
130 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vulncheck9.1CRITICAL
cisa9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Check Point Quantum Security Management up to R81.10 SmartConsole Login improper authentication (EUVD-2026-47700)
vuldb·2026-07-22·CVSS 9.1
CVE-2026-16232 [CRITICAL] Check Point Quantum Security Management up to R81.10 SmartConsole Login improper authentication (EUVD-2026-47700)
A vulnerability was found in Check Point Quantum Security Management and Multi-Domain Security Management up to R81.10 and classified as very critical. The affected element is an unknown function of the component SmartConsole Login. The manipulation results in improper authentication.
This vulnerability is cataloged as CVE-2026-16232. The attack may be launched remotely. Furthermore, there is an exploit available.
GHSA
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full
ghsa_unreviewed·2026-07-22
CVE-2026-16232 [CRITICAL] CWE-287 An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
VulnCheck
Check Point SmartConsole Improper Authentication Vulnerability
vulncheck·2026·CVSS 9.1
CVE-2026-16232 [CRITICAL] CWE-287 Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Affected: Check Point SmartConsole
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherenc
CISA
Check Point SmartConsole Improper Authentication Vulnerability
cisa·2026-07-22·CVSS 9.1
CVE-2026-16232 [CRITICAL] CWE-287 Check Point SmartConsole Improper Authentication Vulnerability
Vulnerability: Check Point SmartConsole Improper Authentication Vulnerability
Affected: Check Point SmartConsole
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ens
No detection rules found.
No public exploits indexed.
Rapid7
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
blogs_rapid7·2026-07-23·CVSS 9.1
CVE-2026-16232 [CRITICAL] CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
## Overview
On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process classified as improper authentication ( CWE-287 ). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.
Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote
Hackernews
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
blogs_hackernews·2026-07-23·CVSS 9.1
CVE-2026-16232 [CRITICAL] Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild .
The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
"Successful exploitation allow
2026-07-22
Published
2026-07-22
Added to CISA KEV
Exploited in the wild