Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2970 articles · 185100 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-16232EXPLOITED
checkpoint · multi-domain_security_management

Authentication Bypass in the SmartConsole Login Process Using an Application Token

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Affected Products

VendorProductVersions
checkpointmulti-domain_security_managementR82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30, R82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsmartconsolecert_advisory90%
checkpointquantum_security_managementcve_cpe95%

References

  • https://support.checkpoint.com/results/sk/sk185169

Related News (13 articles)

Tier D
The Hacker News10d ago
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
→ No new info (linked only)
Tier B
CERT-FR13d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier D
Help Net Security13d ago
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
→ No new info (linked only)
Tier B
BSI Advisories15d ago
[NEU] [hoch] Check Point SmartConsole: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
CSO Online16d ago
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
→ No new info (linked only)
Tier C
Rapid7 Blog16d ago
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
→ No new info (linked only)
Tier D
Help Net Security16d ago
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
→ No new info (linked only)
Tier D
SecurityWeek16d ago
New Check Point Zero-Day Vulnerability Exploited in the Wild
→ No new info (linked only)
Tier D
BleepingComputer16d ago
Check Point warns of SmartConsole zero-day exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News16d ago
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits Check Point (23 juillet 2026)
→ No new info (linked only)
Tier B
CCCS Canada17d ago
Check Point security advisory (AV26-735)
→ No new info (linked only)
Tier C
VulDB17d ago
CVE-2026-16232 | Check Point Quantum Security Management up to R81.10 SmartConsole Login improper authentication
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-287
PublishedJul 22, 2026
Last enriched16d agov4
Tags
zero-dayCISA-known-exploited
Trending Score25
Source articles13
Independent10
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-50751EXPKEV
User Authentication Bypass in VPN Remote Access and Mobile Access
Trending: 88
NONECVE-2026-18574
Authentication Bypass in Check Point Security Management Server
Trending: 35
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 15
HIGHCVE-2026-62145
Local Privilege Escalation in Gaia Portal
Trending: 9
HIGHCVE-2026-50752
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity, cvssEstimate
Jul 22, 2026
Updated: activelyExploited
Jul 22, 2026
Updated: tags
Jul 23, 2026
Actively Exploited
Aug 2, 2026
Exploit Available
Aug 2, 2026

Version History

v4
Last enriched 16d ago
v4Tier D16d ago

Added five attacker IP addresses as indicators of compromise and tagged as zero-day with CISA known exploited vulnerability status.

tags
via BleepingComputer
v3Tier B17d ago

Updated activelyExploited from false to true based on Check Point's confirmation that CVE-2026-16232 is being exploited in the wild.

activelyExploited
via CCCS Canada
v2Tier C17d ago

Article classifies vulnerability as 'very critical' and updates severity from NONE to CRITICAL with estimated CVSS of 9.0

severitycvssEstimate
via VulDB
v117d ago

Initial creation