Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
Brief
Overview
On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS).
By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting.
This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure.
