Check Point SmartConsole: authentication bypass actively exploited
Check Point has fixed a critical vulnerability in the SmartConsole login process, tracked as CVE-2026-16232, which allows an unauthenticated attacker to obtain an application token and gain access with full administrative privileges. Reports indicate that the bug is already being exploited in the wild, although the direct impact currently concerns only a limited number of customers. The flaw affects Security Management and Multi-Domain Security Management products, that is, the servers that distribute policies to firewall gateways, so the potential effect is very broad. If an attacker manages to exploit it, they can modify configurations and security rules instead of merely reading data. ACN and CISA have increased attention on the case by adding or referencing the issue in contexts of known and exploited vulnerabilities. This makes the patch an absolute priority for environments exposed to the Internet or with GUI access that is not strictly controlled. The story is important because it shows how a single authentication bypass can turn into a total compromise of the security infrastructure.
Sources
- U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog — Security Affairs
- CheckPoint: exploitation in the wild of CVE-2026-16232 detected — ACN — CSIRT Italia
- Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) — Help Net Security
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access — The Hacker News
- Check Point patches actively exploited SmartConsole authentication bypass flaw — Security Affairs


Leave a Reply