
#threatreport #LowCompleteness CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild | 23-07-2026 Source: https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication-bypass-exploited-in-the-wild Key details below ↓ 🎯Victims: Network security, Firewall management, Cybersecurity 🔓CVEs: CVE-2026-62144 \[[Vulners](https://vulners.com/cve/CVE-2026-62144)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: Unknown CVE-2024-24919 \[[Vulners](https://vulners.com/cve/CVE-2024-24919)] - CVSS V3.1: *8.6*, - Vulners: Exploitation: True Soft: - checkpoint quantum_spark_firmware (r80.40) CVE-2026-50751 \[[Vulners](https://vulners.com/cve/CVE-2026-50751)] - CVSS V3.1: *9.3*, - Vulners: Exploitation: True Soft: - checkpoint gaia_os (<r81.20, r82, r82.10) CVE-2026-62145 \[[Vulners](https://vulners.com/cve/CVE-2026-62145)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: Unknown CVE-2026-16232 \[[Vulners](https://vulners.com/cve/CVE-2026-16232)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True 📚TTPs: ⚔️Tactics: 1 🛠️Technics: 0 🤖LLM extracted TTPs:` T1098, T1190, T1210, T1550.001, T1562 🧨IOCs: - IP: 6 #threatreport: CVE-2026-16232, a critical vulnerability identified in Check Point's SmartConsole, has been classified as an authentication bypass and has been assigned a CVSS score of 9.1. This vulnerability, associated with improper authentication (CWE-287), allows remote attackers—without requiring authentication—to acquire an application login token. Consequently, they can authenticate to the management server with full administrative privileges, providing them the capacity to modify essential security policies and configurations. The vulnerability is particularly severe as it compromises the Security Management Server, which is crucial in the trust hierarchy of security management. An attacker with administrative access can manipulate various configurations, including altering administrator permissions and VPN settings, potentially undermining logging and monitoring mechanisms. Check Point noted that this flaw had been actively exploited in the wild and detected in a limited number of customer environments. Remote exploitation necessitates that the attacker has network access to the Management Server IP address in systems where Trusted Clients are not restricted. CVE-2026-16232 was included on the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities following Check Point's advisory published on July 22, 2026. Organizations were given an urgent three-day window to respond to this vulnerability before a remediation deadline of July 25, 2026. This vulnerability highlights ongoing issues with Check Point's products, which have recently faced multiple in-the-wild vulnerabilities, underscoring the critical need for timely updates and patches in network security environments. To mitigate CVE-2026-16232, Check Point released Jumbo Hotfixes, also addressing vulnerabilities CVE-2026-62144 and CVE-2026-62145, on the same day as their advisory. Affected organizations are advised to implement these patches on an emergency basis without waiting for the normal patch cycle, especially for versions R81.10, R81.20, R82, and R82.10. Additionally, tools such as Exposure Command, InsightVM, and Nexpose are expected to provide authenticated vulnerability checks to help organizations assess their exposure to this critical vulnerability in their networks.
Post summary
The post reports that Check Point’s SmartConsole authentication bypass (CVE-2026-16232) is actively exploited in the wild, has received CISA notice, and that vendors have issued hotfixes. The vulnerability allows remote attackers to gain full administrative access.







