🔴 Critical | Source: CISA Known Exploited Vulnerabilities
A critical authentication vulnerability in Check Point SmartConsole allows an unauthenticated remote attacker to steal a login token and gain full administrative access to the network security management platform. SmartConsole is the primary interface for managing Check Point firewalls and security policies, meaning a successful exploit could give attackers complete control over an organisation’s network defences. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA’s Known Exploited Vulnerabilities catalogue.
Security Architect’s Take: Patch SmartConsole immediately ahead of the 25 July 2026 CISA deadline, and in the interim restrict access to the SmartConsole management interface to trusted IP ranges only, ideally via a dedicated management VLAN or VPN — exposure of the management plane to the internet should be treated as an emergency. Audit recent SmartConsole authentication logs for unexpected token usage or unfamiliar admin sessions.
Original advisory: CVE-2026-16232: Check Point SmartConsole