## Overview
CISA added CVE-2026-16232 to the Known Exploited Vulnerabilities (KEV) catalog on July 22, 2026. This addition signals a federal deadline for agencies to address the vulnerability. Check Point's SmartConsole contains an authentication bypass flaw that can be exploited remotely.
## Technical Details
The vulnerability allows an unauthenticated remote attacker to obtain an application login token through the SmartConsole login process. Once acquired, the token grants full administrative privileges. Attackers can modify security policies and configurations. Exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point has reported that this vulnerability is being actively exploited, although it has affected a limited number of customers.
## Impact
Successful exploitation of CVE-2026-16232 poses a significant risk to organizations using Check Point SmartConsole. Attackers can alter security settings, potentially leading to unauthorized access and data breaches. The high CVSS score of 9.1 reflects the severity of this vulnerability. Organizations must act quickly to mitigate the risks associated with this flaw.
## Mitigation
Defenders should immediately review their SmartConsole configurations. Restricting access to Trusted Clients is crucial. Check Point is expected to release patches to address this vulnerability. Organizations should apply these updates as soon as they become available. Regularly auditing security policies and configurations can also help mitigate risks associated with this vulnerability.
CSURFACE Threat Sensor