Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-24 ยท updated: 2026-07-24 ยท tags: [cve, zero-day, authentication-bypass, firewall, checkpoint, active-exploitation, kev] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government] ยท au_impact: true

CVE-2026-16232 โ€” Check Point SmartConsole Authentication Bypass

CVE-2026-16232 is a critical authentication bypass vulnerability in Check Point SmartConsole with a CVSS score of 9.3, under active exploitation in the wild.

Details

Field Detail
CVE CVE-2026-16232
Product Check Point SmartConsole
Type Authentication bypass
CVSS 9.3 (Critical)
Exploitation Active exploitation confirmed
Patch Emergency patches released

Impact

An unauthenticated remote attacker can:

  • Obtain application login tokens without authentication
  • Authenticate with full administrative privileges
  • Modify security policies and firewall configurations
  • Potentially disable or reconfigure network security controls

Lotem Finkelstein of Check Point confirmed that a small number of customers have been targeted in active exploitation campaigns.

Remediation

Check Point released emergency patches. Organisations using Check Point SmartConsole should apply patches immediately and audit for indicators of compromise.

Australian Significance

Check Point is widely deployed in Australian government and enterprise networks. Given the active exploitation status and the full admin access granted by this vulnerability, Australian organisations should treat this as a priority patching event.

Related Pages