Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5519 articles · 220951 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-16232EXPLOITED
checkpoint · multi-domain_security_management

Authentication Bypass in the SmartConsole Login Process Using an Application Token

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Affected Products

VendorProductVersions
checkpointmulti-domain_security_managementR82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30, R82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsmartconsolecert_advisory90%
checkpointquantum_security_managementcve_cpe95%

References

  • https://support.checkpoint.com/results/sk/sk185169

Related News (17 articles)

Tier D
BleepingComputer2h ago
Check Point warns of Management Server zero-day exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News5d ago
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
→ No new info (linked only)
Tier D
SecurityWeek11d ago
Check Point Patches Critical VPN Vulnerabilities
→ No new info (linked only)
Tier D
The Hacker News12d ago
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
→ No new info (linked only)
Tier D
The Hacker News55d ago
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
→ No new info (linked only)
Tier B
CERT-FR57d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier D
Help Net Security58d ago
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
→ No new info (linked only)
Tier B
BSI Advisories60d ago
[NEU] [hoch] Check Point SmartConsole: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
CSO Online60d ago
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
→ No new info (linked only)
Tier C
Rapid7 Blog61d ago
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
→ No new info (linked only)
Tier D
Help Net Security61d ago
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
→ No new info (linked only)
Tier D
SecurityWeek61d ago
New Check Point Zero-Day Vulnerability Exploited in the Wild
→ No new info (linked only)
Tier D
BleepingComputer61d ago
Check Point warns of SmartConsole zero-day exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News61d ago
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
→ No new info (linked only)
Tier B
CERT-FR61d ago
Multiples vulnérabilités dans les produits Check Point (23 juillet 2026)
→ No new info (linked only)
Tier B
CCCS Canada62d ago
Check Point security advisory (AV26-735)
→ No new info (linked only)
Tier C
VulDB62d ago
CVE-2026-16232 | Check Point Quantum Security Management up to R81.10 SmartConsole Login improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.1 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-287
PublishedJul 22, 2026
Last enriched61d agov4
Tags
zero-dayCISA-known-exploited
Trending Score110🔥
Source articles17
Independent10
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93616EXPKEV
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
Trending: 112
CRITICALCVE-2026-91843
Stack overflow in login process to the Security Management and Log Servers
Trending: 66
CRITICALCVE-2026-85103
Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
Trending: 48
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 39
NONECVE-2026-18574
Authentication Bypass in Check Point Security Management Server
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity, cvssEstimate
Jul 22, 2026
Updated: activelyExploited
Jul 22, 2026
Updated: tags
Jul 23, 2026
Actively Exploited
Aug 10, 2026
Exploit Available
Aug 10, 2026

Version History

v4
Last enriched 61d ago
v4Tier D61d ago

Added five attacker IP addresses as indicators of compromise and tagged as zero-day with CISA known exploited vulnerability status.

tags
via BleepingComputer
v3Tier B62d ago

Updated activelyExploited from false to true based on Check Point's confirmation that CVE-2026-16232 is being exploited in the wild.

activelyExploited
via CCCS Canada
v2Tier C62d ago

Article classifies vulnerability as 'very critical' and updates severity from NONE to CRITICAL with estimated CVSS of 9.0

severitycvssEstimate
via VulDB
v162d ago

Initial creation