Emergency Security Bulletin: Check Point SmartConsole Authentication Bypass Vulnerability

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg's Cyber Threat Intelligence Team

About:

CVE-2026-16232 is a critical authentication bypass vulnerability affecting Check Point Security Management Server and Multi-Domain Security Management Server.

The vulnerability exists in the SmartConsole login process and may allow an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges.

Successful exploitation could enable attackers to modify security policies, alter system configurations, gain unauthorized administrative access, and potentially compromise the overall security management infrastructure.

Check Point has confirmed active exploitation in the wild affecting a limited number of customers, and CISA has added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) Catalog.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.


VULNERABILITIES

Check Point SmartConsole Authentication Bypass Vulnerability


Identifier: CVE-2026-16232
PoC or Exploitation: Check Point confirms active exploitation in the wild affecting a small number of customers whose Security Management systems were directly exposed to the internet without IP restrictions. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog. 
CVSS Score: 9.3 Critical

Update / Patch:

Affected products:
 
Security Management Server
 
Multi-Domain Security Management Server (MDS)
 
Affected versions:
 
  • R77.30

  • R80

  • R80.10

  • R80.20

  • R80.30

  • R81

  • R81.10

  • R81.20

  • R82

  • R82.10
 
Validated fixed releases:
 
R81.20:
Install Jumbo Hotfix Accumulator Take 158 or later.
 
 
R82:
Install Jumbo Hotfix Accumulator Take 118 or later.
 
 
R82.10:
Install Jumbo Hotfix Accumulator Take 36 or later.
 
 
Official vendor advisory:
 


Description:

CVE-2026-16232 is an authentication-bypass vulnerability in the SmartConsole login process used with Check Point Security Management Server and Multi-Domain Security Management Server.
 
An unauthenticated remote attacker may obtain an application login token and authenticate with full administrative privileges. This access can permit changes to security policies and system configuration.

 

Mitigation Recommendation:

Immediately install the applicable fixed Jumbo Hotfix on R81.20, R82, and R82.10 systems.
 
Limit Trusted Clients, also called GUI clients, to explicitly trusted IP addresses or subnets. Protect access to Security Management systems with a firewall and restrict management connections to trusted sources.
 
Verify that the implied rules for control connections are enabled.
 
Investigate exposed systems for unauthorized SmartConsole logins, application-token activity, administrative actions, and security-policy or configuration changes.