CVE-2026-16232
An authentication bypass in Check Point SmartConsole lets an attacker obtain an admin login token without credentials. The flaw can be exploited remotely to change security policies and configurations. It is rated critical due to its high impact and ease of exploitation.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Check Point SmartConsole (management server) deployments that do not restrict Trusted Clients and are reachable from the internet.
Real-world impact
An attacker can gain full administrative control, modify security policies, and potentially compromise the entire network.
Why this severity
The CVSS score of 9.1 reflects a network‑based attack that requires no user interaction, has low complexity, and grants complete confidentiality and integrity compromise.
What to do about it
- 01Follow the mitigation steps provided by Check Point as per the vendor instructions.
CISA KEV required action
Timeline
- Jul 22, 2026 · 9d agoConfirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 22, 2026 · 8d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 8d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 25, 2026 · 6d agoCISA remediation deadlineFederal agencies are required to remediate by this date.
How it’s attacked
References & advisories
- support.checkpoint.com/results/sk/sk185169mitigationpatchvendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource