THREAT OPS › CVEs › CVE-2026-16232
CVE-2026-16232 — Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Vulnerability details
- Affected productsSmartConsole
- KEV remediation due2026-07-25
Related reporting
- July 2026 CVE Landscaperecordedfuture
- [NVD] CVE-2026-16232 (CRITICAL 9.1) — An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modifnvd
- Check Point security advisory (AV26-735) – Update 1cccs_ca
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-16232 — Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerabilitycisa_kev
- Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)rapid7
- CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wildrapid7
- 27th July – Threat Intelligence Reportcheckpoint_research
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Accessthehackernews
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypassthehackernews