← back
CVE-2026-16232criticalunder attackCWE-287

Authentication Bypass in the SmartConsole Login Process Using an Application Token

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.3epss 71%
from disclosure to weapon0 days
Published on NVDJul 22
1st PoCJul 22
CISA KEVJul 22
exploitation probability
71%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
6 public exploit(s)
Action required by CISAfederal deadline: 2026-07-25

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

An unauthenticated attacker can bypass the login process in Check Point SmartConsole and obtain an administrative token, allowing full control over security policies without needing valid credentials.

Technical detail

CWE-287 authentication bypass in SmartConsole's login process allows remote unauthenticated attackers to directly obtain application tokens with administrative privileges. Exploitation requires network access to the Management Server IP and requires that Trusted Clients restrictions are not configured; successful exploitation grants full modification rights to security policies and configurations.

Summary generated and translated by AI from the official description.
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.