Bleepingcomputer
Check Point SmartConsole Zero-Day Vulnerability Exploited in Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Check Point Software has patched a zero-day vulnerability, CVE-2026-16232, in its SmartConsole GUI admin panel, which is actively exploited. This authentication bypass flaw allows unauthenticated attackers to obtain an application login token, granting full administrative access. Affected systems include Security Management Servers and Multi-Domain Security Management Servers, with exploitation requiring internet access and no restrictions on Trusted Clients. Check Point reports that the vulnerability has impacted a very small number of customers. The Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its catalog of known exploited vulnerabilities, mandating U.S. federal agencies to patch by July 25, 2026. Organizations are urged to prioritize patching to prevent potential attacks. This follows a recent trend of vulnerabilities in Check Point products being exploited by ransomware groups.
Key Points: • CVE-2026-16232 is an authentication bypass vulnerability in Check Point SmartConsole. • Exploitation allows attackers to modify security configurations and policies remotely. • CISA has mandated federal agencies to patch vulnerable systems by July 25, 2026.