Check Point Rushes Patch for Actively Exploited SmartConsole Zero-Day
Check Point Software addresses a critical zero-day vulnerability in its SmartConsole admin panel that attackers actively exploit in the wild. Tracked as CVE-2026-16232, the authentication bypass flaw allows unauthenticated attackers to obtain login tokens and gain administrator privileges on vulnerable Security Management Servers.
The vulnerability enables attackers to modify security policies and configurations once they access a compromised server. Successful remote exploitation requires internet exposure of the Management Server IP address and a lack of restrictions on Trusted Clients. Check Point confirms a small number of customers experience attacks and advises administrators who cannot immediately upgrade to restrict Trusted Clients to trusted IP addresses and block management access from unauthorized sources.
The Cybersecurity and Infrastructure Security Agency adds the flaw to its Known Exploited Vulnerabilities catalog, mandating U.S. federal agencies to patch vulnerable instances by July 25. Administrators can check for compromise by searching SmartConsole audit logs for suspicious authentication methods and known malicious IP addresses associated with the attacks.