🔴 Critical  |  Source: The Hacker News


A critical authentication bypass vulnerability (CVE-2026-16232, CVSS 9.3) in Check Point’s SmartConsole has been actively exploited in the wild, affecting Security Management Server and Multi-Domain Security Management Server. A public proof-of-concept exploit has now been released by Rapid7, significantly lowering the barrier for attackers to reproduce the attack. This flaw could allow an unauthenticated attacker to bypass the login process and gain access to the management plane, putting entire firewall estates at risk.

Security Architect’s Take: Apply Check Point’s patch for CVE-2026-16232 immediately and restrict SmartConsole access to trusted management networks or VPN-only connectivity — given the public PoC, unpatched internet-exposed instances should be treated as potentially compromised and reviewed for indicators of unauthorised access.

Original advisory: Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass