About:
CVE-2026-16232 is a critical authentication bypass vulnerability affecting Check Point Security Management Server and Multi-Domain Security Management Server.
The vulnerability exists in the SmartConsole login process and may allow an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges.
Successful exploitation could enable attackers to modify security policies, alter system configurations, gain unauthorized administrative access, and potentially compromise the overall security management infrastructure.
Check Point has confirmed active exploitation in the wild affecting a limited number of customers, and CISA has added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) Catalog.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
Identifier: CVE-2026-16232
PoC or Exploitation: Check Point confirms active exploitation in the wild affecting a small number of customers whose Security Management systems were directly exposed to the internet without IP restrictions. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog.
CVSS Score: 9.3 Critical
Update / Patch:
Description:
Mitigation Recommendation: