DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-16232PUBLISHED: 2026-07-22
CRITICALCVE-2026-16232★ CISA KEV LISTED

Check Point SmartConsole Authentication Bypass Zero-Day (KEV)

VENDOR: Check Point//PRODUCT: Check Point Security Management Server / Multi-Domain Management
9.3
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

A critical authentication bypass (CWE-287) in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges, enabling unrestricted modification of security policies, VPN configurations, and logging across all managed gateways. Check Point confirmed active exploitation against a limited number of customers with Management Servers directly exposed to the internet without Trusted Client IP restrictions; CISA added it to KEV on July 22, 2026 with a three-day federal deadline of July 25. The Qilin ransomware group was separately observed targeting Check Point appliances during this period. Rapid7 published a public PoC on approximately July 30, 2026.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSSecurity Management / Multi-Domain Management R81.10, R81.20, R82, R82.10 and older versions
  • https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication-bypass-exploited-in-the-wild/
  • https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
  • https://www.helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232/
  • https://support.checkpoint.com/results/sk/sk185169
SHARE BRIEF:✕ Post on Xin Share on LinkedIn