Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Reported exploitedSecurity Management ServerMulti-Domain Security Management Server (MDS)Our summary
A critical authentication bypass vulnerability in Check Point Security Management Server and MDS has been actively exploited, with a public proof-of-concept now available. Tracked as CVE-2026-16232 (CVSS 9.3), the flaw lets attackers gain full administrative privileges without credentials. Rapid7 published a Python script to test for the issue, urging users to apply Check Point’s Jumbo Hotfixes from July 22 immediately.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.