Check Point SmartConsole Authentication Bypass Vulnerability Exploited

Check Point SmartConsole Authentication Bypass Vulnerability Exploited

First seen 29 Jul 2026, 11:02 UTC Rapid7Cybersecuritynewsgithub.com 82% similarity 78.0

Article Content

Browse articles
ThreatCluster

On July 22, 2026, Check Point disclosed CVE-2026-16232, a critical authentication bypass vulnerability in SmartConsole affecting Security Management Server and Multi-Domain Security Management Server (MDS). This flaw allows unauthenticated attackers to gain full administrator access by exploiting a broken trust boundary in the authentication process. The vulnerability was actively exploited in the wild as a zero-day before patches were available. Rapid7 Labs confirmed the vulnerability's exploitation and developed a proof-of-concept (PoC) exploit script. The affected versions include R81.20 and R82.10, and vendor patches have been released to remediate the issue. The vulnerability requires network access to the Management Server and a default Trusted Clients configuration that does not restrict GUI clients. Security professionals are advised to apply the patches immediately to mitigate risks.

Key Points: • CVE-2026-16232 allows unauthenticated access to SmartConsole with full admin privileges. • The vulnerability was actively exploited as a zero-day before patches were available. • Rapid7 Labs has released a PoC exploit script to validate vulnerable systems.

ThreatCluster AI How this analysis works

Timeline

2026-07-22
CVE-2026-16232 published
Check Point disclosed a critical authentication bypass vulnerability affecting SmartConsole.
Rapid7
2026-07-22
CVE-2026-16232 added to CISA KEV
CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Rapid7
2026-07-22
First public PoC released
Rapid7 Labs published a proof-of-concept exploit script for CVE-2026-16232, confirming its exploitability.
Rapid7
2026-07-29
Patches released by Check Point
Check Point confirmed that patches are available to remediate CVE-2026-16232 and prevent exploitation.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story