Exploited in the wild Security Management Server auth-bypass Multi-Domain Security Management Server (MDS) Check Point web-app
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
CVE Tools coverage
A critical authentication bypass vulnerability in Check Point Security Management Server and MDS has been actively exploited, with a public proof-of-concept now available. Tracked as CVE-2026-16232 (CVSS 9.3), the flaw lets attackers gain full administrative privileges without credentials. Rapid7 published a Python script to test for the issue, urging users to apply Check Point’s Jumbo Hotfixes from July 22 immediately.