Check Point SmartConsole Zero-Day Vulnerability Exploited in Attacks

Check Point SmartConsole Zero-Day Vulnerability Exploited in Attacks

First seen 23 Jul 2026, 09:23 UTC Bleepingcomputernvd.nist.govsupport.checkpoint.com 85% similarity 72.9

Article Content

Browse articles
ThreatCluster

Check Point Software has patched a zero-day vulnerability, CVE-2026-16232, in its SmartConsole GUI admin panel, which is actively exploited. This authentication bypass flaw allows unauthenticated attackers to obtain an application login token, granting full administrative access. Affected systems include Security Management Servers and Multi-Domain Security Management Servers, with exploitation requiring internet access and no restrictions on Trusted Clients. Check Point reports that the vulnerability has impacted a very small number of customers. The Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its catalog of known exploited vulnerabilities, mandating U.S. federal agencies to patch by July 25, 2026. Organizations are urged to prioritize patching to prevent potential attacks. This follows a recent trend of vulnerabilities in Check Point products being exploited by ransomware groups.

Key Points: • CVE-2026-16232 is an authentication bypass vulnerability in Check Point SmartConsole. • Exploitation allows attackers to modify security configurations and policies remotely. • CISA has mandated federal agencies to patch vulnerable systems by July 25, 2026.

ThreatCluster AI

Timeline

2024-05-28
CVE-2024-24919 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-50751 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
CVE-2026-16232 published
Check Point disclosed an authentication bypass vulnerability in SmartConsole, allowing unauthorized access.
BleepingComputer
2026-07-22
CVE-2026-16232 added to CISA KEV
CISA included CVE-2026-16232 in its catalog of known exploited vulnerabilities, indicating active exploitation.
nvd.nist.gov
2026-07-23
CISA mandates patching for federal agencies
CISA ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25, 2026.
BleepingComputer

Community

Browse all →