Junglewise Threat Intelligence

CVE-2026-16232: Check Point SmartConsole authentication bypass in login process

CVE-2026-16232 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-07-22

Technologies: Check Point Quantum Security Management. Vendors: Check Point.

Executive brief

Check Point SmartConsole is a management application used to configure and monitor corporate network security policies. A critical vulnerability allows an unauthorized person to bypass the login process and gain full administrative control over the security infrastructure. This could allow an attacker to disable firewalls, change security rules, or gain access to sensitive internal network traffic. Check Point has confirmed that this flaw is currently being exploited in the wild.

Technical details

An authentication bypass vulnerability (CWE-287) exists in the Check Point SmartConsole login process. The flaw allows a remote, unauthenticated attacker to intercept or generate a valid application login token. With this token, the attacker can authenticate to the Management Server with full administrative privileges. Exploitation requires the Management Server's IP to be reachable over the network and a configuration that does not restrict 'Trusted Clients.' Check Point reports active exploitation of this vulnerability. Users should apply the latest Jumbo Hotfix Accumulator for their respective versions (R82.10, R82, R81.20, etc.) to mitigate the risk.

Affected products

  • Check Point Quantum Security Management R82.10 Take 36 and below; R82 Take 118 and below; R81.20 Take 158 and below; R81.10, R81, R80.x, R77.30
  • Check Point Multi-Domain Security Management R82.10 Take 36 and below; R82 Take 118 and below; R81.20 Take 158 and below; R81.10, R81, R80.x, R77.30
  • Check Point SmartConsole All versions used with affected Management Servers

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory
  • 2026-07-22: exploited: Confirmed active exploitation in the wild at time of disclosure.

Related threats