Check Point warns of SmartConsole zero-day exploited in attacks

Check Point warns of SmartConsole zero-day exploited in attacks
Check Point Software has patched CVE-2026-16232, an actively exploited authentication bypass in SmartConsole that can let unauthenticated attackers obtain an administrator application token. CISA has added the flaw to its KEV catalog and urged organizations to patch immediately, with attackers able to alter security policies if the Management Server is exposed and Trusted Clients are not restricted. #CheckPointSoftware #SmartConsole #CVE2026-16232 #CISA

Keypoints

  • Check Point fixed an actively exploited zero-day in SmartConsole.
  • CVE-2026-16232 is an authentication bypass that can grant admin access.
  • Successful exploitation can let attackers change security policies and configurations.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal patching.
  • Admins should patch, restrict Trusted Clients, and review logs for signs of compromise.

Read More: https://www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/