Public PoC Out for Exploited Check Point Admin Bypass
Public PoC is out for CVE-2026-16232, Check Point's CISA KEV-listed admin bypass. Any unpatched SmartConsole server just got cheaper to target — patch or restrict now.
Rapid7 released a public proof-of-concept for CVE-2026-16232 today, July 29 — the authentication bypass in Check Point Security Management Server and Multi-Domain Security Management Server that CISA added to the Known Exploited Vulnerabilities catalog on July 22. The PoC drops on top of confirmed active exploitation that was already underway before this went public. If you haven’t patched, the window is now shorter.
What the Flaw Does
CVE-2026-16232 (CVSS 9.1, critical) is an authentication bypass in the SmartConsole login process. An unauthenticated attacker with network access to the management server port can obtain a valid application login token — no credentials required. That token buys full administrative access: read the policy, modify it, delete it. A compromised SmartConsole management server means an attacker controls the security policy for everything that server manages.
Check Point published its advisory and initial hotfix on July 22, 2026. The company confirmed “a very small number of customers” had been affected at that point.
Why the PoC Release Changes the Math
Before today, exploitation required whoever had already found and weaponized the bug. CISA’s KEV listing confirmed that had happened. Now Rapid7 has published the PoC along with full technical detail. That’s the honest trade-off of responsible disclosure: vendors get a coordinated head start, then the research goes public to push stragglers into patching. It works when people patch. If you haven’t, your management server is now a cheap target.
What to Do — In This Order
1. Apply the July 22 hotfix immediately. The fix is described in Check Point advisory sk185169. This is not a next-patch-cycle item.
2. If you cannot patch right now, restrict Trusted Clients. Enabling Trusted Client restrictions on the Management Server blocks the remote attack vector entirely. This is available without a patch and should be your first action if the hotfix can’t deploy immediately. See the advisory for configuration steps.
3. Review SmartConsole login logs. Look for successful authentications from unfamiliar source IPs, particularly those that occurred before you apply either fix.
4. Verify exposure. The remote attack path requires network access to the management server IP. Environments that already restrict SmartConsole connections to specific trusted management hosts were not exposed via the remote path. Confirm whether yours actually are.
Priority Call
Patch this first. CVSS 9.1 critical, CISA KEV-listed, actively exploited before the PoC was published, now publicly available. That’s every escalation factor at once. A compromised firewall management server is not a “tier two” incident.
We covered the initial KEV addition and admin bypass detail in our July 22 advisory writeup and Rapid7’s technical analysis from yesterday. Today’s PoC release is the third escalation on this vulnerability — confirmed exploitation, CISA catalog listing, and now public weaponization.
- [ CRITICAL ] CVE-2026-16232 Check Point SmartConsole improper authentication
Found this useful? Share it.

