Check Point patches SmartConsole zero-day CVE-2026-16232 after attacks bypassed authentication on management servers

Check Point says attackers are exploiting a flaw in its SmartConsole management software that can let outsiders get administrator-level access to some internet-exposed management servers. The zero-day, CVE-2026-16232, is an authentication bypass in SmartConsole affecting Security Management Server and Multi-Domain Security Management Server (MDS); unauthenticated attackers can obtain an application login token and change security policies if the management server is reachable from the internet and Trusted Clients are not restricted.
Why it matters: Organizations using Check Point management servers could have their security settings changed by an attacker without a valid login, potentially weakening network defenses. This is urgent: patch immediately, restrict management access to trusted IPs, and review SmartConsole audit logs for the application-token indicators Check Point provided.

Sources

New Check Point Zero-Day Vulnerability Exploited in the Wild
Eduard Kovacs 2026.07.23 99% relevant
This article is the same underlying event: Check Point says CVE-2026-16232 was exploited as a zero-day against a limited number of customers with internet-exposed management environments, and it adds details on attack preconditions, admin-token abuse via SmartConsole, available IoCs, and that CISA added the flaw to KEV with a July 25 remediation deadline.
Check Point warns of SmartConsole zero-day exploited in attacks
Sergiu Gatlan 2026.07.23 100% relevant
This article establishes a distinct new event: active exploitation and patching of Check Point SmartConsole authentication-bypass zero-day CVE-2026-16232, which is separate from the previously tracked Check Point VPN zero-day CVE-2026-50751.
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
info@thehackernews.com (The Hacker News) 2026.07.23 99% relevant
This article covers the same underlying event: Check Point's patch for the exploited SmartConsole flaw that can let attackers bypass authentication and gain administrator access, adding another report on the vendor disclosure and remediation.
← Back to all stories