CVE-2026-16232

Published Jul 22, 2026

Last updated a day ago

Exploit knownCVSS critical 9.1
Check Point SmartConsole
Check Point

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-16232 is an authentication bypass vulnerability found in the Check Point SmartConsole login process. This flaw allows an unauthenticated remote attacker to acquire an application login token, which can then be used to authenticate with full administrative privileges. Successful exploitation of this vulnerability enables an attacker to modify security policies and configurations within the affected Check Point systems. Remote exploitation is possible when the Management Server's IP address is accessible via the internet and there are no restrictions on Trusted Clients. Check Point has released security updates to address this issue, and the vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog.

Description
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Source
cve@checkpoint.com
NVD status
Analyzed
Products
multi-domain_security_management, quantum_security_management

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Check Point SmartConsole Improper Authentication Vulnerability
Exploit added on
Jul 22, 2026
Exploit action due
Jul 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

cve@checkpoint.com
CWE-287

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

2

  1. The management plane is supposed to be the part of your security architecture you trust. That trust just got exploited. Check Point disclosed CVE-2026-16232, an authentication bypass affecting Security Management and Multi-Domain Management products. Attackers can obtain an http

    @cytexsmb

    24 Jul 2026

    53 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔒 #CyberSecurity CISA KEV Alert: Check Point and SharePoint Flaws (CVE-2026-16232, CVE-2026-5052… "On July 22, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two…" 🔗 https://t.co/1mUqop3rLY #CyberSecurity #ThreatIntel #cve #zeroday #patchtue

    @SecurityAr58409

    24 Jul 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2026-16232 is an authentication bypass in Check Point's SmartConsole management interface, actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog this week. It is the third authentication bypass in Check Point's management products in

    @juliobmelo

    23 Jul 2026

    330 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  4. #threatreport #LowCompleteness CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild | 23-07-2026 Source: https://t.co/0OceNdruSv Key details below ↓ 🎯Victims: Network security, Firewall management, Cybersecurity 🔓CVEs: CVE-2026-6

    @rst_cloud

    23 Jul 2026

    158 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 🚨 ALERTĂ - Vulnerabilități critice la nivelul Check Point 🔎 Au fost identificate 3 vulnerabilități în produsele Security Management, Multi-Domain Management (MDM), SmartConsole și Gaia Portal: CVE-2026-16232, CVE-2026-62144 și CVE-2026-62145. 👉 https://t.co/FYO

    @DNSC_RO

    23 Jul 2026

    181 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2026-16232 (CVSS 9.3) in Check Point Security Management added to CISA KEV after confirmed exploitation. Unauthenticated token theft enables full admin access. Also patched: CVE-2026-62144 auth bypass/privesc (CVSS 9.3) and CVE-2026-62145 GaiaOS LPE (CVSS 7.5). https://t.co/5

    @MeridianEU

    23 Jul 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 Check Point patched a critical, actively exploited SmartConsole flaw (CVE-2026-16232, CVSS 9.3) letting unauthenticated attackers grab an admin login token — CISA's added it to the KEV list with a July 25 patch deadline. Two more bugs fixed too: an admin-command bypass

    @techepages

    23 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🛡️We added Check Point SmartConsole vulnerability CVE-2026-16232 & Microsoft SharePoint vulnerability CVE-2026-50522 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/zNyW

    @CISACyber

    22 Jul 2026

    13121 Impressions

    9 Retweets

    23 Likes

    4 Bookmarks

    4 Replies

    2 Quotes

  9. 🚨*CVE* CVE-2026-16232 An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token an… https://t.co/BPwHzwr2KR ----- Traducción: CVE-2026-16232 Una… https://t.co/utmtNg

    @infoflowcloud

    22 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations