Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has issued security updates addressing multiple vulnerabilities in its Security Management and Multi-Domain Security Management products, including a critical flaw currently being actively exploited. The most severe issue, CVE-2026-16232 (CVSS score: 9.3), allows unauthenticated attackers to bypass authentication and gain full administrative access via the SmartConsole login process. This could enable attackers to alter security policies and configurations remotely. The flaw impacts several versions of Check Point's software, including R77.30 through R82.10. A patch is available, and users are advised to apply the latest Jumbo hotfix immediately. CISA has also added this vulnerability to its KEV catalog, mandating federal agencies to remediate by July 25, 2026.