Check Point warns of SmartConsole zero-day exploited in attacks
Check Point Software has released a fix for a critical zero-day vulnerability affecting its SmartConsole interface, which is currently being exploited in real-world attacks. The flaw, identified as CVE-2026-16232, enables unauthenticated attackers to bypass authentication and gain administrative privileges by stealing an application token. Once inside, adversaries can alter security policies and configurations on affected systems like the Security Management Server and Multi-Domain Security Management Server (MDS). The vulnerability requires that the server’s IP be accessible over the internet and that Trusted Client restrictions are disabled. CISA has added the issue to its list of known exploited vulnerabilities and directed U.S. federal agencies to apply patches by July 25. Organizations are strongly advised to update or implement mitigations such as restricting Trusted Clients to specific IPs.