Vulnary
← back to the feed
Critical· 9.1actively exploitedofficial fix available

CVE-2026-16232

An authentication bypass in Check Point SmartConsole lets an attacker obtain an admin login token without credentials. The flaw can be exploited remotely to change security policies and configurations. It is rated critical due to its high impact and ease of exploitation.

publishedJul 22, 2026
last modifiedJul 23, 2026
sourcesNVD · CISA-KEV
severity · cvss
9.1
critical · how bad it is
exploitation · epss
70%
99th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 21, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Check Point SmartConsole (management server) deployments that do not restrict Trusted Clients and are reachable from the internet.

02

Real-world impact

An attacker can gain full administrative control, modify security policies, and potentially compromise the entire network.

03

Why this severity

The CVSS score of 9.1 reflects a network‑based attack that requires no user interaction, has low complexity, and grants complete confidentiality and integrity compromise.

04

What to do about it

official fix available
recommended steps
  1. 01Follow the mitigation steps provided by Check Point as per the vendor instructions.

CISA KEV required action

05

Timeline

  1. Jul 22, 2026 · 9d ago
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  2. Jul 22, 2026 · 8d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  3. Jul 22, 2026 · 8d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
  4. Jul 25, 2026 · 6d ago
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →