Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-16232EXPLOITED
checkpoint · multi-domain_security_management

Authentication Bypass in the SmartConsole Login Process Using an Application Token

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Affected Products

VendorProductVersions
checkpointmulti-domain_security_managementR82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30, R82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsmartconsolecert_advisory90%
checkpointquantum_security_managementcve_cpe95%

References

  • https://support.checkpoint.com/results/sk/sk185169

Related News (13 articles)

Tier D
The Hacker News25d ago
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
→ No new info (linked only)
Tier B
CERT-FR28d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier D
Help Net Security28d ago
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
→ No new info (linked only)
Tier B
BSI Advisories30d ago
[NEU] [hoch] Check Point SmartConsole: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
CSO Online31d ago
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
→ No new info (linked only)
Tier C
Rapid7 Blog31d ago
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
→ No new info (linked only)
Tier D
Help Net Security31d ago
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
→ No new info (linked only)
Tier D
SecurityWeek31d ago
New Check Point Zero-Day Vulnerability Exploited in the Wild
→ No new info (linked only)
Tier D
BleepingComputer31d ago
Check Point warns of SmartConsole zero-day exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News31d ago
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
→ No new info (linked only)
Tier B
CERT-FR32d ago
Multiples vulnérabilités dans les produits Check Point (23 juillet 2026)
→ No new info (linked only)
Tier B
CCCS Canada32d ago
Check Point security advisory (AV26-735)
→ No new info (linked only)
Tier C
VulDB32d ago
CVE-2026-16232 | Check Point Quantum Security Management up to R81.10 SmartConsole Login improper authentication
→ No new info (linked only)
CVSS 3.19.1 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-287
PublishedJul 22, 2026
Last enriched31d agov4
Tags
zero-dayCISA-known-exploited
Trending Score3
Source articles13
Independent10
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-18574
Authentication Bypass in Check Point Security Management Server
Trending: 12
CRITICALCVE-2026-50751EXPKEV
User Authentication Bypass in VPN Remote Access and Mobile Access
Trending: 11
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 3
HIGHCVE-2026-62145
Local Privilege Escalation in Gaia Portal
Trending: 2
HIGHCVE-2026-50752
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity, cvssEstimate
Jul 22, 2026
Updated: activelyExploited
Jul 22, 2026
Updated: tags
Jul 23, 2026
Actively Exploited
Aug 10, 2026
Exploit Available
Aug 10, 2026

Version History

v4
Last enriched 31d ago
v4Tier D31d ago

Added five attacker IP addresses as indicators of compromise and tagged as zero-day with CISA known exploited vulnerability status.

tags
via BleepingComputer
v3Tier B32d ago

Updated activelyExploited from false to true based on Check Point's confirmation that CVE-2026-16232 is being exploited in the wild.

activelyExploited
via CCCS Canada
v2Tier C32d ago

Article classifies vulnerability as 'very critical' and updates severity from NONE to CRITICAL with estimated CVSS of 9.0

severitycvssEstimate
via VulDB
v132d ago

Initial creation