Search
Find merged stories by title or summary.
Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure.
Infosec News Nuggets — July 23, 2026
Check Point Warns of SmartConsole Zero-Day Exploited in Attacks Check Point patched CVE-2026-16232, an authentication bypass vulnerability in its SmartConsole GUI admin panel that allows unauthenticated attackers to obtain an application login token usable to authenticate with administrator privileges on a vulnerable Security Management Server. Successful exploitation requires the Management Server IP to be exposed to internet access with no restrictions on Trusted Clients, after which an attacker can modify security policies and configurations across the affected deployment; Check Point says the flaw has affected “a very small number of customers” so far.
CVE-2026-16232 - Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
