ctipilot.ch

Check Point SmartConsole authentication bypass to full admin (exploited)

cve · CVE-2026-16232

Coverage timeline
1
first 2026-07-23 → last 2026-07-23
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Check Point Multi-Domain Security ManagementCheck Point Security ManagementCheck Point SmartConsole

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-23/check-point-smartconsole-auth-bypass-cve-2026-16232 · ATT&CK page ↗

Story timeline

  1. 2026-07-23CVE-2026-16232 — Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1)
    trending-vulnerabilitiesCheck Point patches an actively-exploited SmartConsole authentication bypass granting full management-server admin

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • blog.checkpoint.com1 (33%)
  • cisa.gov1 (33%)
  • euvd.enisa.europa.eu1 (33%)

explore in graph

Entries about Check Point SmartConsole authentication bypass to full admin (exploited) (1)

2026-07-23 · view entry permalink →

HIGHCVE-2026-16232exploitedNATOA1

CVE-2026-16232 — Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1)

The flaw sits in the SmartConsole login process of Check Point Security Management and Multi-Domain Security Management (CWE-287): an unauthenticated remote attacker who can reach the Management Server obtains an application login token and uses it to authenticate to SmartConsole with full administrative privileges, from which they can rewrite firewall security policy and configuration (Check Point Software, 2026-07-22). The precondition is narrow but severe: the Management Server must be exposed directly to the internet with no Trusted-Clients (GUI-client IP allow-list) restriction — Check Point states this "only affects a very specific configuration" and confirms active exploitation against "a handful of customers with specific configurations" (Check Point Software, 2026-07-22). CISA added the CVE to its Known Exploited Vulnerabilities catalogue the same day it was disclosed (CISA, 2026-07-22). The score is carried as 9.1 (NVD's assignment) though Check Point's advisory prints 9.3; both are critical. No exploiting cluster has been named.

This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions.

Yes, for a handful of customers with specific configurations

Check Point Software 2026-07-22
vulnerability23 Jul 04:34Zmulti-sourceOpen finding ↗