CVE Tools

Хакеры атакуют 0-day в Check Point SmartConsole

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedCheck Point SmartConsoleSecurity Management

Our summary

Check Point has warned customers of a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrative privileges, and modify security policies. It is already being actively used in real-world attacks. According to Check Point, several clients were targeted where their management systems were directly accessible online without IP restrictions. Attackers can use this zero-day to obtain login tokens, authenticate through SmartConsole as administrators, and alter system settings. Patches, temporary mitigations, and indicators of compromise have been released. CISA has also added the flaw to its catalog of known exploited vulnerabilities.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store