A critical improper-authentication flaw in Check Point SmartConsole lets an unauthenticated remote attacker steal an application login token and authenticate with full administrative privileges, and it is being actively exploited in the wild.
What Is It
CVE-2026-16232 is an authentication bypass vulnerability (CWE-287) in the Check Point SmartConsole login process. An unauthenticated remote attacker can obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
Why It Matters
CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2026-07-22, confirming active exploitation. Check Point states it is aware the vulnerability is being exploited and that a very small number of customers have been affected. CISA's SSVC assessment rates exploitation as "active," automatable "yes," and technical impact "total." Because the flaw grants full administrative control over a security management server, including the ability to rewrite firewall and security policy, a successful attack can undermine the defensive posture of an entire environment. Known ransomware campaign use is currently listed as "Unknown."
What's Vulnerable
The following Check Point products are affected:
- Quantum Security Management and Multi-Domain Security Management:
- R82.10 with Jumbo Hotfix Take 36 or below
- R82 with Jumbo Hotfix Take 118 or below
- R81.20 with Jumbo Hotfix Take 158 or below
- R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
Patch Status
CISA's required action is to apply mitigations per vendor instructions in accordance with BOD 26-04 and CISA's "Forensics Triage Requirements," with a due date of 2026-07-25. Organizations should follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable, and evaluate each asset's internet exposure. Vendor guidance is published in Check Point advisory sk185169.