Authentication Bypass in Check Point SmartConsole Login Process
CVE-2026-16232

9.3CRITICAL

Key Information:

Badges

📈 Trended📈 Score: 16,200💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 71%🦅 CISA Reported📰 News Worthy

What is CVE-2026-16232?

CVE-2026-16232 is a serious vulnerability found in the Check Point SmartConsole, a management interface used for configuring and monitoring security policies in network environments. This vulnerability allows an unauthenticated remote attacker to gain access to the application login token, which can be leveraged to authenticate as an administrator. As a result, attackers can manipulate security policies and configurations at will. The risk associated with this vulnerability is significant as it grants complete administrative privileges to an adversary, enabling them to potentially alter the defensive posture of an organization, thus compromising its overall security infrastructure. For exploitation to occur, the attacker needs internet access to the Management Server IP and a configuration that permits access from trusted clients.

Potential impact of CVE-2026-16232

  1. Full Administrative Control: Successful exploitation can provide an attacker with full administrative rights, allowing them to modify or disable vital security measures and configurations that protect the organization's network.

  2. Data Breach Risks: With the ability to alter security policies, attackers could facilitate unauthorized access to sensitive data, leading to data breaches and associated legal or financial repercussions.

  3. Widespread Network Compromise: The capability to change security settings may allow an attacker to pivot through the network, enabling lateral movements that could lead to the installation of malware or ransomware, further crippling the organization’s operational capabilities.

CISA has reported CVE-2026-16232

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-16232 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below

Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below

Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public - Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses

CVE-2026-16232 lets an unauthenticated attacker seize full admin control of Check Point's management console. Check Point confirms in-the-wild attacks, and a Rapid7 PoC is now public.

1 week ago

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Ravie LakshmananJul 29, 2026Vulnerability / Enterprise Security

2 weeks ago

Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access - PoC Released

A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available.

2 weeks ago

References

EPSS Score

71% chance of being exploited in the next 30 days.

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 📈

    Vulnerability started trending

  • 💰

    Used in Ransomware

  • 📰

    First article discovered by The Hacker News

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.