🔴 Critical | Source: The Hacker News
Check Point has patched a critical authentication bypass vulnerability (CVE-2026-16232, CVSS 9.3) in its SmartConsole management interface that is already being actively exploited in the wild. The flaw allows an unauthenticated attacker to gain full administrative access to Security Management and Multi-Domain Management (MDSM) environments. Because these are central management platforms, a successful exploit could give an attacker control over an organisation’s entire firewall and security policy estate.
Security Architect’s Take: Apply Check Point’s security updates to all Security Management and MDSM installations immediately — do not wait for a scheduled maintenance window given confirmed active exploitation. In the interim, restrict SmartConsole access to trusted management networks via firewall ACLs and review recent admin-level audit logs for any anomalous or unrecognised sessions.
Original advisory: Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access