ctipilot.ch
← Back to the live brief
HIGHCVE-2026-16232exploitedNATOA1vulnerability

CVE-2026-16232 — Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1)

discovered 2026-07-23 04:34 UTCrun 2026-07-23T0409Z-intel3 sourcesmulti-source

The flaw sits in the SmartConsole login process of Check Point Security Management and Multi-Domain Security Management (CWE-287): an unauthenticated remote attacker who can reach the Management Server obtains an application login token and uses it to authenticate to SmartConsole with full administrative privileges, from which they can rewrite firewall security policy and configuration (Check Point Software, 2026-07-22). The precondition is narrow but severe: the Management Server must be exposed directly to the internet with no Trusted-Clients (GUI-client IP allow-list) restriction — Check Point states this "only affects a very specific configuration" and confirms active exploitation against "a handful of customers with specific configurations" (Check Point Software, 2026-07-22). CISA added the CVE to its Known Exploited Vulnerabilities catalogue the same day it was disclosed (CISA, 2026-07-22). The score is carried as 9.1 (NVD's assignment) though Check Point's advisory prints 9.3; both are critical. No exploiting cluster has been named.

This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions.

Yes, for a handful of customers with specific configurations

Check Point Software 2026-07-22

Defender actions

  • Restrict SmartConsole 'Trusted Clients' (the GUI-client IP allow-list) on every internet-reachable Check Point Security Management and Multi-Domain Management server to known administrator IPs now — the network-layer restriction neutralises the token bypass independent of patch state — and apply the 2026-07-22 Jumbo Hotfix.
  • On any Management Server that was internet-exposed without a Trusted-Clients restriction, review SmartConsole authentication logs for logins authenticated via application token from outside the admin IP range and audit the security-policy and object change history for unexpected administrative changes.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.