Check Point SmartConsole Authentication Bypass Exploited
Check Point has patched a critical authentication bypass, CVE-2026-16232, in SmartConsole, the admin panel for its Security Management and Multi-Domain Security Management servers, that lets an unauthenticated remote attacker grab a valid application login token and log in with full administrator rights, without a password.
TA2026211 July 24, 2026TA2026211A1CVE-2026-16232CWE-287Summary
First Seen: Prior to July 22, 2026
Affected Products: Check Point Security Management Server, Check Point Multi-Domain Security Management Server (MDS)
Check Point has patched a critical flaw in SmartConsole, the admin panel used to manage its Security Management and Multi-Domain Security Management (MDS) servers. Tracked as CVE-2026-16232, the flaw is an authentication bypass in the SmartConsole login process that lets an unauthenticated remote attacker grab a valid application login token and use it to log in with full administrator rights, without any password. Check Point found the bug during a routine internal review and confirmed it was already being exploited against a small number of customers before a fix existed. Exploitation only works when the Management Server is reachable from the internet and does not restrict Trusted Clients (GUI clients).
CVE at a Glance
| CVE | Name | Affected Product |
|---|---|---|
CVE-2026-16232 | Check Point SmartConsole Improper Authentication Vulnerability | Check Point Security Management / Multi-Domain Security Management |
Vulnerability Details
#1 — Improper Authentication in the SmartConsole Login Flow
CVE-2026-16232 is classified as improper authentication (CWE-287). The weakness lives in the SmartConsole login process, the workflow responsible for authenticating administrators to a Check Point Security Management or Multi-Domain Security Management server.
#2 — An Application Login Token Handed to an Unauthenticated Party
Rather than requiring valid credentials, the flawed SmartConsole login flow can be manipulated into handing an application login token to an unauthenticated party. That token is a trusted piece of authentication material, so once an attacker holds it, they can present it back to the management server and be treated as a fully authenticated administrator. In effect, the bug converts an anonymous network connection into an admin session without ever cracking or phishing a password.
#3 — Remote, Network-Based, but Configuration-Gated
The attack against CVE-2026-16232 is remote and network-based, but it is gated by configuration. Successful exploitation requires the Management Server's IP address to be reachable over the internet and the Trusted Clients (GUI clients) setting to leave connecting hosts unrestricted.
#4 — Affected Releases and Jumbo Hotfix Accumulators
The vulnerability spans a wide range of releases of the Security Management Server and Multi-Domain Security Management Server, including R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Fixes are delivered through Jumbo Hotfix Accumulators: R82.10 from Take 36, R82 from Take 118, and R81.20 from Take 158. The older, largely end-of-support branches (R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30) have no specified fix, so organizations still running them must lean on mitigation and upgrade planning.
#5 — Confirmed Active Exploitation
Check Point has confirmed active exploitation of CVE-2026-16232. According to the vendor, the issue surfaced during a routine internal review, and follow-up analysis showed that the flaw had been exploited, affecting a small number of customers who have since been notified.
Affected Versions, CPE, and CWE
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-16232 | Check Point Security Management Server / Multi-Domain Security Management (R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10) | cpe:2.3:a:checkpoint:multi-domain_security_management:*:*:*:*:*:*:*:* | CWE-287 |
Recommendations
Install the latest Jumbo Hotfix Accumulator for your release without waiting for a routine maintenance window, using Take 36 or later for R82.10, Take 118 or later for R82, and Take 158 or later for R81.20. This is the only step that removes the underlying flaw; every other measure below merely reduces exposure until the hotfix is in place.
For environments where the hotfix cannot be applied at once, limit Trusted Clients (GUI clients) to specific trusted IP addresses or subnets rather than allowing "Any," place management access behind a firewall that only permits authorized IP addresses, and confirm that implied rules for control connections are enabled. Following the Check Point Hardening Best Practices Guide shrinks the attack surface, though it does not close the vulnerability itself.
Organizations running R81.10, R81, R80.30, R80.20, R80.10, R80, or R77.30 have no vendor fix for CVE-2026-16232, so plan a migration to a supported release that can receive the Jumbo Hotfix. In the interim, the mitigation steps above are the primary line of defense for these deployments.
Treat any internet-exposed Check Point management server as potentially targeted and investigate even after patching. In SmartConsole, review Logs & Monitor / Logs & Events for traffic to or from the published attacker IP addresses, and search the Audit Logs view for events where the authentication method is an application token. Also examine administrator, SmartConsole, API, and application-token activity for anything unexpected.
Potential MITRE ATT&CK TTPs
T1190Exploit Public-Facing ApplicationT1550Use Alternate Authentication MaterialT1550.001: Application Access TokenT1562Impair DefensesT1068Exploitation for Privilege EscalationT1588Obtain CapabilitiesT1588.006: VulnerabilitiesIndicators of Compromise (IOCs)
| Type | Value |
|---|---|
| IPv4 | 151[.]241[.]99[.]207 |
| IPv4 | 151[.]241[.]99[.]233 |
| IPv4 | 158[.]62[.]198[.]182 |
| IPv4 | 192[.]142[.]10[.]99 |
| IPv4 | 139[.]28[.]37[.]250 |
References & Patch Links
Patch Link
References
July 24, 2026 • 07:30 AM © 2026 All Rights are Reserved by Hive Pro 