CVE Tools

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

Rapid7 BlogBy Jonah Burgess4 min read

Reported exploitedSecurity ManagementMulti-Domain Management

Our summary

A critical authentication bypass flaw, CVE-2026-16232, in Check Point’s SmartConsole has been actively exploited in the wild. The vulnerability affects Security Management and Multi-Domain Management systems, allowing attackers to gain full administrative access without credentials. Check Point issued a security advisory on July 22, 2026, confirming active exploitation and urging immediate patching. The flaw was added to CISA’s Known Exploited Vulnerabilities catalog with a three-day window for remediation. Affected versions include R82.10, R82, R81.20, and others, all of which require installing the latest Jumbo Hotfix. Rapid7 advises checking for signs of compromise, especially in exposed environments.

Read at Rapid7 Blog

Below is the opening; the full story is at Rapid7 Blog.

From Rapid7 Blog

Overview

On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login process classified as improper authentication (CWE-287). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.…

Continue at Rapid7 Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store