CVE-2026-16232
Check Point SmartConsole Improper Authentication Vulnerability
Description
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Description as published by the source, in English.
Key facts
- Published
- 2026-07-22
- Last modified
- 2026-08-10
- Assigned by
- cve@checkpoint.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Scored by
- nvd@nist.gov (NVD Primary)
- Probability of exploitation
-
71.4 %
higher than 99 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Yes, see references
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-07-22, with a remediation deadline of 2026-07-25 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Checkpoint | Multi-domain Security Management | r81.20 | Affected |
| Checkpoint | Multi-domain Security Management | r82 | Affected |
| Checkpoint | Multi-domain Security Management | r82.10 | Affected |
| Checkpoint | Multi-domain Security Management | ≥ r77.30, < r81.20 | Affected |
| Checkpoint | Quantum Security Management | r81.20 | Affected |
| Checkpoint | Quantum Security Management | r82 | Affected |
| Checkpoint | Quantum Security Management | r82.10 | Affected |
| Checkpoint | Quantum Security Management | ≥ r77.30, < r81.20 | Affected |
Weakness type
-
CWE-287: Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1040: Network Sniffing
- T1134: Access Token Manipulation
- T1185: Browser Session Hijacking
- T1505.003: Web Shell
- T1548: Abuse Elevation Control Mechanism
- T1550.001: Application Access Token
- T1557: Adversary-in-the-Middle
- T1563: Remote Service Session Hijacking
References
- https://support.checkpoint.com/results/sk/sk185169
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232
Related at Berigo
Articles
-
Check Point patches two critical management server flaws
Mentions this CVE
2026-07-22
Check Point has fixed CVE-2026-16232 and CVE-2026-62144, both giving unauthenticated access to the management server; the first has been seen exploit…
-
Critical authentication bypass in Check Point management servers
Same product
2026-08-05
Check Point has fixed a critical vulnerability in Security Management Server and Multi-Domain Security Management Server. CVE-2026-18574 is scored at…
-
Meta recovery tool abused for account takeover
Same product
2026-06-08
Meta says 20,225 Instagram accounts may have been compromised after attackers abused an AI-assisted account recovery support tool.
-
Check Point patches critical VPN authentication bypass
Same product
2026-06-08
A logic flaw in certificate validation lets an unauthenticated attacker establish a VPN connection without a valid password. Exploitation has been ob…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.