Rapid7
Critical Zero-Day Vulnerability in Check Point SmartConsole Exploited
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 22, 2026, Check Point disclosed CVE-2026-16232, a critical authentication bypass vulnerability in SmartConsole affecting Security Management Server and Multi-Domain Security Management Server (MDS). This flaw allows unauthenticated attackers to gain full administrative access by exploiting the SmartConsole login process. The vulnerability is actively exploited in the wild as a zero-day, with a proof-of-concept (PoC) exploit available. Exploitation requires network access to the Management Server and a default Trusted Clients configuration. Check Point has confirmed that patches are available to remediate this vulnerability. Security professionals are urged to apply the patches immediately to mitigate risks. The vulnerability was reported to have been actively exploited before the patches were released.
Key Points: • CVE-2026-16232 allows unauthenticated access to Check Point SmartConsole. • Exploitation requires network access and a default configuration setting. • Patches have been released and confirmed to remediate the vulnerability.