Check Point has disclosed an actively exploited zero-day authentication bypass in SmartConsole, tracked as CVE-2026-16232, that can let unauthenticated attackers obtain an application login token and gain administrator access. The flaw affects exposed Security Management Server and Multi-Domain Security Management Server deployments, and CISA has added it to its known exploited vulnerabilities catalog while urging rapid patching. #CheckPoint #SmartConsole #CVE-2026-16232 #CISA
Keypoints
- CVE-2026-16232 is an authentication bypass in Check Point SmartConsole.
- Attackers can obtain an application token and log in with admin privileges.
- Exploitation requires exposed management access and unrestricted Trusted Clients.
- Successful compromise can lead to changes in security policies and configurations.
- CISA has added the flaw to its known exploited vulnerabilities catalog and ordered urgent patching.