CVE-2026-16232: Check Point SmartConsole authentication bypass in Quantum Security Management added to CISA KEV with in-the-wild exploitation reported
CVE-2026-16232 is a High-severity authentication bypass (CWE-287) in the Check Point SmartConsole login process, exploitable via application tokens, that enables takeover of Quantum Security Management firewall management servers. It was disclosed and added…
CVE-2026-16232 is an authentication bypass (CWE-287) affecting the SmartConsole login process of Check Point Quantum Security Management when application tokens are used. Check Point's advisory sk185169 rates the issue High severity; per the advisory text reviewed, it provides no CVSS score, affected-version list, or exploitation status. Web reports state the vulnerability was disclosed on July 22, 2026, added to CISA's Known Exploited Vulnerabilities catalog the same day with a remediation deadline of July 25, 2026, and that exploitation in the wild was confirmed by Rapid7, Check Point Research, and other vendors; a public proof of concept was released. Successful exploitation allows attackers to take over firewall management servers. A workaround is available, and federal agencies must comply with BOD 26-04 patching guidance. Source note: the sk185169 advisory text (later report) contains no exploitation details, while the earlier web report states in-the-wild exploitation was confirmed by multiple vendors.
- CVE-2026-16232 is an authentication bypass (CWE-287) in the Check Point SmartConsole login process when using application tokens
- Affected product: Check Point Quantum Security Management; exploitation enables takeover of firewall management servers
- Check Point advisory sk185169 rates the issue High severity; the advisory text provides no CVSS score, affected-version list, or exploitation status
- Disclosed July 22, 2026; added to CISA KEV the same day with remediation due July 25, 2026 (3-day deadline)
- In-the-wild exploitation confirmed by Rapid7, Check Point Research, and other vendors (per web reports); a public PoC was released
- A workaround is available; federal agencies must comply with CISA BOD 26-04 patching guidance
Coverage timelineoldest first · each row is one article
- · 11d agoCVE-2026-16232: Checkpoint Quantum Security Management auth bypass ...
Web discovery (articles for new exploits & KEV entries)· 84
Attackers exploit Check Point SmartConsole authentication bypass CVE-2026-16232 to take over Quantum Security Management firewall servers; CISA added it to KEV.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-16232 | Authentication Bypass in Check Point SmartConsole Grants Full Admin Access Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released. Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing. | 9.3 | 72% | KEV |
| largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no… |