VULNERABILITY OVERVIEW
A critical authentication bypass (CWE-287) in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges, enabling unrestricted modification of security policies, VPN configurations, and logging across all managed gateways. Check Point confirmed active exploitation against a limited number of customers with Management Servers directly exposed to the internet without Trusted Client IP restrictions; CISA added it to KEV on July 22, 2026 with a three-day federal deadline of July 25. The Qilin ransomware group was separately observed targeting Check Point appliances during this period. Rapid7 published a public PoC on approximately July 30, 2026.
CVSS BREAKDOWN
Security Management / Multi-Domain Management R81.10, R81.20, R82, R82.10 and older versionsCITATIONS
- → https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication-bypass-exploited-in-the-wild/
- → https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
- → https://www.helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232/
- → https://support.checkpoint.com/results/sk/sk185169