CVE-2026-16232
Check Point SmartConsole
Summary
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful…
Published: 2026-07-22 · In KEV since: 2026-07-22
Analysis
🔴 Critical — actively exploited
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Active exploitation confirmed by CISA (KEV).
- Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The vector encodes how it's exploited (translated above, in the analysis). Break it down in the CVSS tool →
Sources: CISA KEV · EPSS · FIRST.org · NVD. Analysis derived from the CVSS vector and exploitation status (no AI). Informational; always verify against the vendor's official advisory.