Check Point SmartConsole Auth Bypass Allows Admin Privileges
CVE-2026-16232 Published on July 22, 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Known Exploited Vulnerability
This Check Point SmartConsole Improper Authentication Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
The following remediation steps are recommended / required by July 25, 2026: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab
Vulnerability Analysis
CVE-2026-16232 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. This vulnerability is known to be actively exploited by threat actors in an automatable fashion. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2026-16232 has been classified to as an authentification vulnerability or weakness.
Affected Versions
checkpoint Quantum Security Management:- Version R82.10 with Jumbo Hotfix Take 36 or below is affected.
- Version R82 with Jumbo Hotfix Take 118 or below is affected.
- Version R81.20 with Jumbo Hotfix Take 158 or below is affected.
- Version R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 is affected.
- Version R82.10 with Jumbo Hotfix Take 36 or below is affected.
- Version R82 with Jumbo Hotfix Take 118 or below is affected.
- Version R81.20 with Jumbo Hotfix Take 158 or below is affected.
- Version R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.