CVE Tools
Back to feed
Exploited in the wild Security Management auth-bypass Multi-Domain Management Check Point network-edge

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

Rapid7 Blog·By Jonah Burgess··4 min read
CVE Tools coverage

A critical authentication bypass flaw, CVE-2026-16232, in Check Point’s SmartConsole has been actively exploited in the wild. The vulnerability affects Security Management and Multi-Domain Management systems, allowing attackers to gain full administrative access without credentials. Check Point issued a security advisory on July 22, 2026, confirming active exploitation and urging immediate patching. The flaw was added to CISA’s Known Exploited Vulnerabilities catalog with a three-day window for remediation. Affected versions include R82.10, R82, R81.20, and others, all of which require installing the latest Jumbo Hotfix. Rapid7 advises checking for signs of compromise, especially in exposed environments.

Overview

On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login process classified as improper authentication (CWE-287). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.…

Continue reading on Rapid7 Blog