CVE-2026-16232: Checkpoint Quantum Security Management auth bypass ...
Attackers exploit Check Point SmartConsole authentication bypass CVE-2026-16232 to take over Quantum Security Management firewall servers; CISA added it to KEV.
CVE-2026-16232 is an authentication bypass (CWE-287) in the SmartConsole login process of Check Point Quantum Security Management, exploitable via an application token. Disclosed July 22, 2026, it was added to CISA's Known Exploited Vulnerabilities catalog the same day with remediation due July 25. Rapid7, Check Point Research and other vendors confirmed exploitation in the wild, and a public PoC was released. A workaround is available, and federal agencies must comply with BOD 26-04 patching guidance.
- Auth bypass in SmartConsole login enables takeover of firewall management servers
- Added to CISA KEV on July 22, 2026 with a 3-day remediation deadline
- Public PoC released; in-the-wild exploitation confirmed by multiple vendors
- Workaround available; BOD 26-04 requirements apply to federal agencies
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-16232 | Authentication Bypass in Check Point SmartConsole Grants Full Admin Access Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released. Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing. | 9.3 | 72% | KEV |
| largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no… |
Full article492 words · extracted from cve.tools · click to collapse
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Exploitability
CISA Known Exploited Vulnerability
Added to KEV:Jul 22, 2026
Remediation due:Jul 25, 2026
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Workaround Available
Attack Graph
Products CVE Techniques Tactics
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniques
Initial Access
References
News mentions
11
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
en·The Hacker News·Jul 29, 2026
Exploited
Security Management Server auth-bypass
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
en·Rapid7 Blog·Jul 28, 2026
Exploited
SmartConsole zero-day
Хакеры атакуют 0-day в Check Point SmartConsole
ru-ru·Хакер (xakep.ru)·Jul 27, 2026
Exploited
Check Point SmartConsole zero-day
27th July – Threat Intelligence Report
en-us·Check Point Research·Jul 27, 2026
Roundup
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
en·The Hacker News·Jul 27, 2026
Research
ai-ml
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
en-us·Help Net Security·Jul 26, 2026
Roundup
ServiceNow AI Platform
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
en·Rapid7 Blog·Jul 23, 2026
Exploited
Security Management auth-bypass
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
en-us·Help Net Security·Jul 23, 2026
Exploited
Check Point Security Management auth-bypass
New Check Point Zero-Day Vulnerability Exploited in the Wild
en-us·SecurityWeek·Jul 23, 2026
Exploited
Security Management zero-day
Check Point warns of SmartConsole zero-day exploited in attacks
en-us·BleepingComputer·Jul 23, 2026
Exploited
SmartConsole zero-day
Was this CVE page helpful?
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-16232 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
Text extracted automatically; images, tables and formatting may be missing. Original: https://cve.tools/v/CVE-2026-16232