All news & advisories
Actively exploited

CVE-2026-16232: Actively Exploited Vulnerability

CVE-2026-16232 CVSS 9.1 CISA KEV · actively exploited
Who it affects
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
What to do
Patch immediately — prioritise internet-facing systems.

CVE-2026-16232 is a critical-severity vulnerability (CVSS 9.1), listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as actively exploited.

Summary

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Remediation

It is actively exploited — apply the vendor’s patch immediately and prioritize internet-facing systems. Patch-management tools that can deploy and verify the fix include Action1, Automox, ManageEngine Patch Manager Plus, ManageEngine Endpoint Central. See our best patch management ranking.

Sources

Data as of July 23, 2026. Sources: nvd.nist.gov, support.checkpoint.com, cisa.gov. Figures are pulled from public vendor and security data and refreshed automatically.
Back to all news & advisories