CVE Tools
Back to feed
Exploited in the wild SmartConsole zero-day Security Management Server Check Point Software auth-bypass

Check Point warns of SmartConsole zero-day exploited in attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

Check Point Software has released a fix for a critical zero-day vulnerability affecting its SmartConsole interface, which is currently being exploited in real-world attacks. The flaw, identified as CVE-2026-16232, enables unauthenticated attackers to bypass authentication and gain administrative privileges by stealing an application token. Once inside, adversaries can alter security policies and configurations on affected systems like the Security Management Server and Multi-Domain Security Management Server (MDS). The vulnerability requires that the server’s IP be accessible over the internet and that Trusted Client restrictions are disabled. CISA has added the issue to its list of known exploited vulnerabilities and directed U.S. federal agencies to apply patches by July 25. Organizations are strongly advised to update or implement mitigations such as restricting Trusted Clients to specific IPs.