BigTech CompaniesCybersecurityNewswireTechnologyWhat's Buzzing

Check Point SmartConsole zero-day actively exploited in attacks

▼ Summary

– Check Point Software patched an actively exploited zero-day authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole admin GUI.
– The flaw lets unauthenticated attackers obtain an admin login token and change security configurations on vulnerable Management Servers.
– Successful exploitation requires the Management Server IP to be exposed to the internet without Trusted Client IP restrictions.
– CISA added the flaw to its known exploited vulnerabilities catalog, ordering U.S. federal agencies to patch by July 25.
– Admins unable to patch immediately should restrict Trusted Clients to specific IPs and block non-authorized management access.

The Check Point SmartConsole zero-day vulnerability, tracked as CVE-2026-16232, is now being actively exploited in real-world attacks, prompting urgent action from both the vendor and U.S. federal authorities. Check Point Software has released a patch for this critical authentication bypass flaw in its SmartConsole graphical user interface (GUI) admin panel.

This authentication bypass vulnerability enables unauthenticated attackers to steal an application login token, granting them administrator-level privileges on affected systems. Once inside a vulnerable Security Management Server or Multi-Domain Security Management Server (MDS), adversaries can alter security configurations and policies at will.

Exploitation is only possible under specific conditions: the Management Server IP must be exposed to the internet via remote access, and Trusted Clients (GUI clients) must have no IP restrictions in place. “During a routine BLAST review, we discovered a few vulnerabilities. Following a thorough analysis, we identified one of those in the wild, affecting a handful of customers,” explained Lotem Finkelstein, Check Point’s VP of Research. “This only affects a very specific configuration , when Management is exposed directly to the internet without IP restrictions. All affected customers have been notified. All Smart-1 Cloud customers are already protected.”

For administrators unable to upgrade immediately, Check Point recommends following the Hardening Best Practices Guide, limiting Trusted Clients to approved IP addresses or subnets, and blocking management access for all unauthorized IPs.

To detect potential compromise, admins should search SmartConsole logs using the query `Authentication method: application token` under Logs & Monitor / Logs & Events > Audit Logs View, then run a specific SmartConsole query targeting known malicious IPs, including addresses such as 151.241.99.207 and 158.62.198.182.

On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog, ordering U. S. federal agencies to patch affected SmartConsole instances by Saturday, July 25, as required by Binding Operational Directive (BOD) 26-04. “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the agency warned. Although BOD 26-04 applies only to federal agencies, CISA urged all organizations to prioritize patching this flaw to prevent incoming attacks.

This is not the first time Check Point products have been targeted. In June, CISA ordered federal agencies to secure Check Point Remote Access VPN and Mobile Access deployments against another zero-day authentication bypass, CVE-2026-50751, which was exploited by the Qilin ransomware gang. Two years ago, the agency flagged CVE-2024-24919 in Check Point’s Quantum Security Gateways as actively exploited by ransomware groups, linking it to NailaoLocker ransomware attacks as reported by Orange Cyberdefense CERT.

(Source: BleepingComputer)

Topics

zero-day vulnerability 95% authentication bypass 92% security management server 88% internet exposure risk 85% patch urgency 83% cisa directive 80% check point software 78% exploitation in wild 76% security configuration change 74% trusted clients limitation 72%