Critical Zero-Day Vulnerability in Check Point SmartConsole Exploited

Critical Zero-Day Vulnerability in Check Point SmartConsole Exploited

First seen 29 Jul 2026, 11:02 UTC Rapid7GbhackersCybersecuritynewsgithub.com 82% similarity 72.9

Article Content

Browse articles
ThreatCluster

On July 22, 2026, Check Point disclosed CVE-2026-16232, a critical authentication bypass vulnerability in SmartConsole affecting Security Management Server and Multi-Domain Security Management Server (MDS). This flaw allows unauthenticated attackers to gain full administrative access by exploiting the SmartConsole login process. The vulnerability is actively exploited in the wild as a zero-day, with a proof-of-concept (PoC) exploit available. Exploitation requires network access to the Management Server and a default Trusted Clients configuration. Check Point has confirmed that patches are available to remediate this vulnerability. Security professionals are urged to apply the patches immediately to mitigate risks. The vulnerability was reported to have been actively exploited before the patches were released.

Key Points: • CVE-2026-16232 allows unauthenticated access to Check Point SmartConsole. • Exploitation requires network access and a default configuration setting. • Patches have been released and confirmed to remediate the vulnerability.

ThreatCluster AI How this analysis works

Timeline

2026-07-22
CVE-2026-16232 published
Check Point disclosed a critical authentication bypass vulnerability affecting SmartConsole.
Rapid7
2026-07-22
CVE added to CISA KEV
CVE-2026-16232 was added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Rapid7
2026-07-22
First public PoC released
A proof-of-concept exploit script for CVE-2026-16232 was made publicly available, confirming the vulnerability's exploitation potential.
Cybersecuritynews
2026-07-29
Patches confirmed effective
Check Point confirmed that the patches for CVE-2026-16232 successfully remediate the vulnerability.
Rapid7

Community

Browse all →