Check Point SmartConsole Authentication Bypass Exploited

Red | Vulnerability
Download Now
Check Point SmartConsole Authentication Bypass Exploited | TA2026211 | HivePro Threat Advisory
Threat Advisory • Vulnerability Report

Check Point SmartConsole Authentication Bypass Exploited

Check Point has patched a critical authentication bypass, CVE-2026-16232, in SmartConsole, the admin panel for its Security Management and Multi-Domain Security Management servers, that lets an unauthenticated remote attacker grab a valid application login token and log in with full administrator rights, without a password.

Actively Exploited CVE-2026-16232 Auth Bypass Config-Gated Exposure Admiralty Code: A1 TA2026211
Date of Publication
July 24, 2026
TA Number
TA2026211
Admiralty Code
A1
First Seen
Prior to July 22, 2026
CVE ID
CVE-2026-16232
Affected Products
Check Point Security Management / MDS
Vulnerability Type
Improper Authentication
CWE ID
CWE-287
Report Type
Vulnerability Report

Summary

First Seen: Prior to July 22, 2026

Affected Products: Check Point Security Management Server, Check Point Multi-Domain Security Management Server (MDS)

Check Point has patched a critical flaw in SmartConsole, the admin panel used to manage its Security Management and Multi-Domain Security Management (MDS) servers. Tracked as CVE-2026-16232, the flaw is an authentication bypass in the SmartConsole login process that lets an unauthenticated remote attacker grab a valid application login token and use it to log in with full administrator rights, without any password. Check Point found the bug during a routine internal review and confirmed it was already being exploited against a small number of customers before a fix existed. Exploitation only works when the Management Server is reachable from the internet and does not restrict Trusted Clients (GUI clients).

CVE at a Glance
CVENameAffected Product
CVE-2026-16232Check Point SmartConsole Improper Authentication VulnerabilityCheck Point Security Management / Multi-Domain Security Management

Vulnerability Details

#1 — Improper Authentication in the SmartConsole Login Flow

CVE-2026-16232 is classified as improper authentication (CWE-287). The weakness lives in the SmartConsole login process, the workflow responsible for authenticating administrators to a Check Point Security Management or Multi-Domain Security Management server.

#2 — An Application Login Token Handed to an Unauthenticated Party

Rather than requiring valid credentials, the flawed SmartConsole login flow can be manipulated into handing an application login token to an unauthenticated party. That token is a trusted piece of authentication material, so once an attacker holds it, they can present it back to the management server and be treated as a fully authenticated administrator. In effect, the bug converts an anonymous network connection into an admin session without ever cracking or phishing a password.

#3 — Remote, Network-Based, but Configuration-Gated

The attack against CVE-2026-16232 is remote and network-based, but it is gated by configuration. Successful exploitation requires the Management Server's IP address to be reachable over the internet and the Trusted Clients (GUI clients) setting to leave connecting hosts unrestricted.

#4 — Affected Releases and Jumbo Hotfix Accumulators

The vulnerability spans a wide range of releases of the Security Management Server and Multi-Domain Security Management Server, including R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Fixes are delivered through Jumbo Hotfix Accumulators: R82.10 from Take 36, R82 from Take 118, and R81.20 from Take 158. The older, largely end-of-support branches (R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30) have no specified fix, so organizations still running them must lean on mitigation and upgrade planning.

#5 — Confirmed Active Exploitation

Check Point has confirmed active exploitation of CVE-2026-16232. According to the vendor, the issue surfaced during a routine internal review, and follow-up analysis showed that the flaw had been exploited, affecting a small number of customers who have since been notified.

Affected Versions, CPE, and CWE
CVE IDAffected ProductsAffected CPECWE ID
CVE-2026-16232Check Point Security Management Server / Multi-Domain Security Management (R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10)cpe:2.3:a:checkpoint:multi-domain_security_management:*:*:*:*:*:*:*:*CWE-287

Recommendations

01
Patch Affected Management Servers Immediately

Install the latest Jumbo Hotfix Accumulator for your release without waiting for a routine maintenance window, using Take 36 or later for R82.10, Take 118 or later for R82, and Take 158 or later for R81.20. This is the only step that removes the underlying flaw; every other measure below merely reduces exposure until the hotfix is in place.

02
Restrict Trusted Clients and Management Exposure

For environments where the hotfix cannot be applied at once, limit Trusted Clients (GUI clients) to specific trusted IP addresses or subnets rather than allowing "Any," place management access behind a firewall that only permits authorized IP addresses, and confirm that implied rules for control connections are enabled. Following the Check Point Hardening Best Practices Guide shrinks the attack surface, though it does not close the vulnerability itself.

03
Upgrade End-of-Support Versions

Organizations running R81.10, R81, R80.30, R80.20, R80.10, R80, or R77.30 have no vendor fix for CVE-2026-16232, so plan a migration to a supported release that can receive the Jumbo Hotfix. In the interim, the mitigation steps above are the primary line of defense for these deployments.

04
Hunt for Signs of Compromise

Treat any internet-exposed Check Point management server as potentially targeted and investigate even after patching. In SmartConsole, review Logs & Monitor / Logs & Events for traffic to or from the published attacker IP addresses, and search the Audit Logs view for events where the authentication method is an application token. Also examine administrator, SmartConsole, API, and application-token activity for anything unexpected.


Potential MITRE ATT&CK TTPs

Initial Access
T1190Exploit Public-Facing Application
Defense Evasion
T1550Use Alternate Authentication Material
T1550.001: Application Access Token
Defense Evasion
T1562Impair Defenses
Privilege Escalation
T1068Exploitation for Privilege Escalation
Resource Development
T1588Obtain Capabilities
T1588.006: Vulnerabilities

Indicators of Compromise (IOCs)

TypeValue
IPv4151[.]241[.]99[.]207
IPv4151[.]241[.]99[.]233
IPv4158[.]62[.]198[.]182
IPv4192[.]142[.]10[.]99
IPv4139[.]28[.]37[.]250

References & Patch Links