๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-16232: Check Point SmartConsole Improper Authentication Vulnerability
Summary
Check Point SmartConsole has an improper authentication vulnerability (a flaw where the system doesn't properly verify user identity) that allows an unauthenticated attacker to obtain a login token (a digital credential) and gain full administrative access without needing legitimate credentials. This vulnerability is actively being exploited by attackers in real-world incidents.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions at https://support.checkpoint.com/results/sk/sk185169/, following CISA's BOD 26-04 guidance for prioritizing security updates. If mitigations are unavailable, discontinue use of the product. The patch deadline is 2026-07-25.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
July 21, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16232
First tracked: July 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%