Rapid7 Critical Zero-Day Vulnerability in Check Point SmartConsole Exploited
Article Content
- •CVE-2026-16232 allows unauthenticated access to Check Point SmartConsole.
- •Exploitation requires network access and a default configuration setting.
- •Patches have been released and confirmed to remediate the vulnerability.
On July 22, 2026, Check Point disclosed CVE-2026-16232, a critical authentication bypass vulnerability in SmartConsole affecting Security Management Server and Multi-Domain Security Management Server (MDS). This flaw allows unauthenticated attackers to gain full administrative access by exploiting the SmartConsole login process. The vulnerability is actively exploited in the wild as a zero-day, with a proof-of-concept (PoC) exploit available. Exploitation requires network access to the Management Server and a default Trusted Clients configuration. Check Point has confirmed that patches are available to remediate this vulnerability. Security professionals are urged to apply the patches immediately to mitigate risks. The vulnerability was reported to have been actively exploited before the patches were released.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Check Point and CVE-2026-16232 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Check Point VPN Vulnerabilities Disclosed and Patched On September 9, 2026, Check Point disclosed two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both with a CVSS score of 9.8, affecting its Quantum product line. These vulnerabilities allow unauthenticated remote code execution through improper certificate trust validation and a heap-based buffer…
Critical Check Point Flaw Allows Unauthenticated Root Code Execution Check Point disclosed a critical vulnerability, CVE-2026-91843, rated 9.8 on the CVSS scale, that enables unauthenticated attackers to execute code as root on Security Management and Log Servers. This stack-based buffer overflow occurs during the login process when an excessively long username is submitted, allowing…