SYS::ONLINE
Wasteland.
Briefs1497
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-16232 2026-07-22

CVE-2026-16232: Check Point SmartConsole Authentication Bypass Grants Full Admin Access

"A critical improper-authentication flaw in Check Point SmartConsole lets an unauthenticated remote attacker steal an application login token and authenticate with full administrative privileges, and it is being actively…"

A critical improper-authentication flaw in Check Point SmartConsole lets an unauthenticated remote attacker steal an application login token and authenticate with full administrative privileges, and it is being actively exploited in the wild.

What Is It

CVE-2026-16232 is an authentication bypass vulnerability (CWE-287) in the Check Point SmartConsole login process. An unauthenticated remote attacker can obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.

Why It Matters

CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2026-07-22, confirming active exploitation. Check Point states it is aware the vulnerability is being exploited and that a very small number of customers have been affected. CISA's SSVC assessment rates exploitation as "active," automatable "yes," and technical impact "total." Because the flaw grants full administrative control over a security management server, including the ability to rewrite firewall and security policy, a successful attack can undermine the defensive posture of an entire environment. Known ransomware campaign use is currently listed as "Unknown."

What's Vulnerable

The following Check Point products are affected:

Patch Status

CISA's required action is to apply mitigations per vendor instructions in accordance with BOD 26-04 and CISA's "Forensics Triage Requirements," with a due date of 2026-07-25. Organizations should follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable, and evaluate each asset's internet exposure. Vendor guidance is published in Check Point advisory sk185169.

Sources