Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4618 articles · 179956 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-16232EXPLOITED
check point · smartconsole

Authentication Bypass in the SmartConsole Login Process Using an Application Token

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Affected Products

VendorProductVersions
check pointsmartconsoleR82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30, R82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30

References

  • https://support.checkpoint.com/results/sk/sk185169

Related News (9 articles)

Tier D
CSO Online3h ago
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
→ No new info (linked only)
Tier C
Rapid7 Blog11h ago
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
→ No new info (linked only)
Tier D
Help Net Security12h ago
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
→ No new info (linked only)
Tier D
SecurityWeek14h ago
New Check Point Zero-Day Vulnerability Exploited in the Wild
→ No new info (linked only)
Tier D
BleepingComputer15h ago
Check Point warns of SmartConsole zero-day exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News16h ago
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
→ No new info (linked only)
Tier B
CERT-FR23h ago
Multiples vulnérabilités dans les produits Check Point (23 juillet 2026)
→ No new info (linked only)
Tier B
CCCS Canada1d ago
Check Point security advisory (AV26-735)
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-16232 | Check Point Quantum Security Management up to R81.10 SmartConsole Login improper authentication
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-287
PublishedJul 22, 2026
Last enriched14h agov4
Tags
zero-dayCISA-known-exploited
Trending Score115🔥
Source articles9
Independent9
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-10847EXP
Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS
HIGHCVE-2026-48132
VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
HIGHCVE-2026-48133EXP
Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
MEDIUMCVE-2026-48134EXP
SQL injection issue in UserCheck Portal when DLP Software Blade is active
HIGHCVE-2026-48135EXP
HTTP service can incorrectly process malformed HTTP requests

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity, cvssEstimate
Jul 22, 2026
Updated: activelyExploited
Jul 22, 2026
Actively Exploited
Jul 23, 2026
Updated: tags
Jul 23, 2026

Version History

v4
Last enriched 14h ago
v4Tier D14h ago

Added five attacker IP addresses as indicators of compromise and tagged as zero-day with CISA known exploited vulnerability status.

tags
via BleepingComputer
v3Tier B1d ago

Updated activelyExploited from false to true based on Check Point's confirmation that CVE-2026-16232 is being exploited in the wild.

activelyExploited
via CCCS Canada
v2Tier C1d ago

Article classifies vulnerability as 'very critical' and updates severity from NONE to CRITICAL with estimated CVSS of 9.0

severitycvssEstimate
via VulDB
v11d ago

Initial creation