CVE-2026-16232

Published Jul 22, 2026

Last updated 8 days ago

Exploit knownCVSS critical 9.3
Zero-day
ICS
Business logic
OT
Check Point SmartConsole
Check Point

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-16232 is an authentication bypass vulnerability found in the Check Point SmartConsole login process. This flaw allows an unauthenticated remote attacker to acquire an application login token, which can then be used to authenticate with full administrative privileges. Successful exploitation of this vulnerability enables an attacker to modify security policies and configurations within the affected Check Point systems. Remote exploitation is possible when the Management Server's IP address is accessible via the internet and there are no restrictions on Trusted Clients. Check Point has released security updates to address this issue, and the vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog.

Description
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Source
cve@checkpoint.com
NVD status
Analyzed
Products
multi-domain_security_management, quantum_security_management

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Check Point SmartConsole Improper Authentication Vulnerability
Exploit added on
Jul 22, 2026
Exploit action due
Jul 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

cve@checkpoint.com
CWE-287

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2026-16232 — CVSS 9.3 CRITICAL A critical authentication bypass in Check Point SmartConsole allows unauthenticated remote attackers to obtai ⚠️ Actively exploited in the wild. 🔎 Details & PoC: https://t.co/MGJ3Y2eCgO #CVE #CyberSecurity #InfoSec #CheckPoi

    @stem__shop

    16 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. JUST IN: Alleged Sale of Full-Combat Exploit for CVE-2026-16232 A seller (display107) is offering a “full combat version” of an exploit targeting CVE-2026-16232. Key findings:
• Claimed capability: temporary full administrative access (approximately two hours)
• All

    @CyberWatch05

    6 Aug 2026

    204 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-of-the-Day: CVE-2026-16232 — Check Point SmartConsole auth bypass CVSS: 9.3 | EPSS: 71% An unauthenticated attacker can forge a login token and gain full admin access to your Security Management Server. Exploited as a zero-day before a patch existed. #CVE #infosec 🧵

    @YourDailyCVE

    4 Aug 2026

    8 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-16232](https://t.co/j1OP1T1Iy5) An authentication bypass vul... https://t.co/j1OP1T1Iy5 #Vulnerability #CVE #ZeroDay

    @MalwareObserver

    2 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ Vulnerabilidades en productos Check Point ❗ CVE-2026-62145 ❗ CVE-2026-62144 ❗ CVE-2026-16232 ➡️ Más info: https://t.co/Tue0lk6nSA https://t.co/nSXBznUAss

    @CERTpy

    29 Jul 2026

    177 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Check Point Zero-Day CVE-2026-16232 aktiv exploitet: Authentication Bypass ermöglicht Admin-Rechte. CISA ordnet Patch bis 25. Juli an. #CVE #PatchNow https://t.co/eVbrpIHlwA

    @wall_your_x

    29 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2026-16232: a public proof of concept now exists for an actively exploited Check Point management bypass. Check Point patched the flaw on July 22, 2026 and disclosed that it had already been exploited as a zero-day against a handful of customers. CISA added it to the Known h

    @CTIAcademy

    29 Jul 2026

    235 Impressions

    2 Retweets

    4 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  8. New critical flaws! Check Point zero-day (CVE-2026-16232) allows admin takeover, Azure DNS (CVE-2026-58275) enables traffic redirection. DNS poisoning via Wi-Fi gateways also active. High risk to data privacy & integrity in transit. #Cybersecurity #News

    @YourAnon_irc

    27 Jul 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Check Point SmartConsole CVE-2026-16232 (CVSS 9.3): forge one token, get full admin on the console managing every firewall you run. No creds, no MFA. Patched, already CISA KEV. 2nd exploited Check Point CVE in 6 weeks. Patch now. https://t.co/XV3el902Gp  #CVE #CheckPoint #CISA

    @DIESEC_GmbH

    27 Jul 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 Alerta en Check Point Detectadas 3 vulnerabilidades (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) con elevación de privilegios. La CVE-2026-16232 registra explotación activa. 🛡️ Aplica los parches recomendados. #Ciberseguridad #CheckPoint #InfoSec https://t.co/40

    @BetoDay

    26 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CISA added CVE-2026-16232 and CVE-2026-50522 to its KEV Catalog on July 22, 2026, based on evidence of active exploitation by malicious cyber actors. https://t.co/eJyDNzhqQx

    @f1tym1

    26 Jul 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. 🚨 CVE-2026-16232: A critical vulnerability in Check Point Security Management servers allows remote attackers to gain full administrative privileges without a password. #CheckPoint #CVE #CyberSecurity #ThreatWire

    @ThreatWire_

    26 Jul 2026

    3010 Impressions

    5 Retweets

    20 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  13. Check Point zero-day exploited: A Check Point SmartConsole vulnerability (CVE-2026-16232) is being actively exploited, and defenders should apply available patches without delay.

    @webenstein_

    26 Jul 2026

    112 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token https://t.co/d22UkiB221

    @RoryCrave

    26 Jul 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 CRITICAL: CVE-2026-16232 in Check Point SmartConsole allows unauthenticated remote attackers to gain FULL ADMIN access via stolen login tokens. Actively exploited (CISA KEV). Patch immediately. Due date: 2026-07-25 #CVE #PatchNow https://t.co/28qRvaBL7t

    @DFIR_Lab

    26 Jul 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Recent critical vulns: Knot Resolver DNS-over-QUIC RCE (CVE-2026-66374), epa4all TLS MiTM (CVE-2026-48021), & Check Point auth bypass (CVE-2026-16232) threaten data privacy/integrity in transit. Act now! [July 25, 2026] #Cybersecurity #NetworkSecurity #ZeroDays

    @YourAnon_irc

    25 Jul 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. The management plane is supposed to be the part of your security architecture you trust. That trust just got exploited. Check Point disclosed CVE-2026-16232, an authentication bypass affecting Security Management and Multi-Domain Management products. Attackers can obtain an http

    @cytexsmb

    24 Jul 2026

    58 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🔒 #CyberSecurity CISA KEV Alert: Check Point and SharePoint Flaws (CVE-2026-16232, CVE-2026-5052… "On July 22, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two…" 🔗 https://t.co/1mUqop3rLY #CyberSecurity #ThreatIntel #cve #zeroday #patchtue

    @SecurityAr58409

    24 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. CVE-2026-16232 is an authentication bypass in Check Point's SmartConsole management interface, actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog this week. It is the third authentication bypass in Check Point's management products in

    @juliobmelo

    23 Jul 2026

    330 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  20. #threatreport #LowCompleteness CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild | 23-07-2026 Source: https://t.co/0OceNdruSv Key details below ↓ 🎯Victims: Network security, Firewall management, Cybersecurity 🔓CVEs: CVE-2026-6

    @rst_cloud

    23 Jul 2026

    158 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. 🚨 ALERTĂ - Vulnerabilități critice la nivelul Check Point 🔎 Au fost identificate 3 vulnerabilități în produsele Security Management, Multi-Domain Management (MDM), SmartConsole și Gaia Portal: CVE-2026-16232, CVE-2026-62144 și CVE-2026-62145. 👉 https://t.co/FYO

    @DNSC_RO

    23 Jul 2026

    181 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. CVE-2026-16232 (CVSS 9.3) in Check Point Security Management added to CISA KEV after confirmed exploitation. Unauthenticated token theft enables full admin access. Also patched: CVE-2026-62144 auth bypass/privesc (CVSS 9.3) and CVE-2026-62145 GaiaOS LPE (CVSS 7.5). https://t.co/5

    @MeridianEU

    23 Jul 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 Check Point patched a critical, actively exploited SmartConsole flaw (CVE-2026-16232, CVSS 9.3) letting unauthenticated attackers grab an admin login token — CISA's added it to the KEV list with a July 25 patch deadline. Two more bugs fixed too: an admin-command bypass

    @techepages

    23 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🛡️We added Check Point SmartConsole vulnerability CVE-2026-16232 & Microsoft SharePoint vulnerability CVE-2026-50522 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/zNyW

    @CISACyber

    22 Jul 2026

    13121 Impressions

    9 Retweets

    23 Likes

    4 Bookmarks

    4 Replies

    2 Quotes

  25. 🚨*CVE* CVE-2026-16232 An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token an… https://t.co/BPwHzwr2KR ----- Traducción: CVE-2026-16232 Una… https://t.co/utmtNg

    @infoflowcloud

    22 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations