Check Point CVE-2026-16232: SmartConsole auth bypass exploited
Check Point shipped a hotfix for CVE-2026-16232, a SmartConsole login-flow auth bypass letting an unauthenticated attacker seize full admin control of the firewall management server. It is being actively exploited; CISA added it to KEV with a July 25 remediation deadline for US federal agencies.
Check Point has confirmed CVE-2026-16232, an authentication bypass in the SmartConsole login flow of Security Management and Multi-Domain Management, is being exploited in the wild. An unauthenticated attacker can obtain an application login token and use it to sign in to SmartConsole with full admin privileges, then alter security policy and configuration.
Key points
- Severity: rated critical (CVSS 9.1 per Rapid7's analysis); Check Point confirms active exploitation affecting a small number of customers.
- Affected: R81.10, R81.20, R82, R82.10, including some end-of-life releases.
- Exploit conditions: the Management server IP is internet-reachable with no Trusted Clients (GUI client) restrictions.
- Fix: Check Point released a jumbo hotfix on July 22, 2026; patch immediately and restrict Trusted Clients to trusted IP ranges per its Hardening guide.
- Compliance: CISA added CVE-2026-16232 to its KEV catalog with a July 25 deadline for US federal agencies.
FAQ
Am I affected? If you run Check Point Security Management/Multi-Domain on R81.10-R82.10 with an internet-facing management server, treat yourself as at risk and patch now. Is patching enough? Patching is mandatory, but also restrict Trusted Clients by IP and review SmartConsole logins for anomalies given active exploitation. Why the urgency? It is a pre-auth takeover of firewall management infrastructure; CISA's July 25 deadline signals how urgent it is.
Technical detail and mitigations are in Check Point's official advisory (SK185169) - see Read original.