Check Point has fixed an actively exploited zero-day vulnerability in SmartConsole, the graphical administration interface for its security management products.
The flaw, tracked as CVE-2026-16232, allows an unauthenticated attacker to obtain an application login token and authenticate with administrator-level privileges.
Check Point said the Check Point SmartConsole zero-day has affected a very small number of customers. However, successful exploitation can allow attackers to change security policies and security configurations on vulnerable management servers.
CVE-2026-16232 Enables Administrator Access
The vulnerability affects Check Point Security Management Server and Multi-Domain Security Management Server deployments.
An attacker who exploits the flaw can obtain a login token without first authenticating. They can then use that token to access the SmartConsole environment with administrator privileges.
From there, the attacker may alter security settings and policies. This could weaken an organisation’s defences, create new access paths or interfere with security monitoring.
Remote exploitation requires the affected Management Server IP address to be accessible from the internet. In addition, the deployment must not restrict SmartConsole access to trusted GUI clients.
Check Point Urges Customers to Patch
Check Point has released updates to address CVE-2026-16232 and urged customers to install them as soon as possible.
Organisations that cannot patch immediately should limit Trusted Clients to approved IP addresses or subnets. They should also block management access from unauthorised IP addresses and follow Check Point’s hardening guidance.
Restricting remote access to management interfaces can reduce the chance of exploitation. Security teams should avoid exposing these systems directly to the internet whenever possible.
How to Check for Signs of Compromise
Administrators can review SmartConsole audit logs for suspicious authentication activity.
Check Point advises customers to look for records that contain the authentication method “application token”. Teams should also investigate activity connected to the following IP addresses:
- 151.241.99.207
- 151.241.99.233
- 158.62.198.182
- 192.142.10.99
- 139.28.37.250
These indicators do not confirm a compromise on their own. However, they may help administrators identify potentially suspicious SmartConsole activity that needs further review.
CISA Adds Flaw to Known Exploited Vulnerabilities List
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog on Wednesday.
CISA ordered US federal agencies to patch vulnerable SmartConsole systems by Saturday, July 25, under Binding Operational Directive 26-04.
Although the directive applies only to federal civilian agencies, CISA urged all organisations to prioritise the update. The agency warned that attackers frequently target authentication flaws and that such vulnerabilities can pose significant risks.
Check Point Faces Repeated Authentication Flaw Attacks
The Check Point SmartConsole zero-day follows other recently exploited authentication bypass vulnerabilities affecting the company’s products.
In June, CISA ordered federal agencies to secure Check Point Remote Access VPN and Mobile Access products against CVE-2026-50751. The Qilin ransomware group reportedly exploited that flaw in zero-day attacks.
CISA also flagged CVE-2024-24919 in Check Point Quantum Security Gateways as actively exploited in 2024. Researchers linked attacks involving the vulnerability to NailaoLocker ransomware activity.
Because attackers are actively exploiting CVE-2026-16232, organisations should patch exposed SmartConsole environments immediately and review logs for signs of unauthorised access.


0 responses to “Check Point SmartConsole Zero-Day Exploited in Active Attacks”