Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
- Vendor
- Check Point
- Product
- SmartConsole
- CVSS
- 9.1
- EPSS (exploit probability)
- N/A
- Status
- kev
- Published
An authentication bypass in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. NVD scores it 9.1 (Critical) under CVSS 3.1. The vulnerability was published to NVD on July 22, 2026.
CISA added CVE-2026-16232 to the Known Exploited Vulnerabilities catalog on July 22, 2026. Check Point confirmed active exploitation in its advisory, noting that “a very small number of customers” have been affected.
Exposure condition: Remote exploitation requires network access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Environments that restrict SmartConsole connections to specific trusted hosts are not exposed via the remote path.
Remediation: Apply the patched build described in Check Point security advisory sk185169. If patching is not immediately possible, enabling Trusted Client restrictions on the Management Server blocks the remote attack vector. See NVD record for CVE-2026-16232.
Full coverage: Check Point SmartConsole auth bypass — CISA KEV, active exploitation.
