CVE Tools

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

The Hacker NewsBy The Hacker News

Reported exploitedSmartConsoleSecurity Management Server

Our summary

Check Point has issued security updates addressing multiple vulnerabilities in its Security Management and Multi-Domain Security Management products, including a critical flaw currently being actively exploited. The most severe issue, CVE-2026-16232 (CVSS score: 9.3), allows unauthenticated attackers to bypass authentication and gain full administrative access via the SmartConsole login process. This could enable attackers to alter security policies and configurations remotely. The flaw impacts several versions of Check Point's software, including R77.30 through R82.10. A patch is available, and users are advised to apply the latest Jumbo hotfix immediately. CISA has also added this vulnerability to its KEV catalog, mandating federal agencies to remediate by July 25, 2026.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store