Start with Identity
← Blog
News

A Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers

CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Management servers, then use it with full administrative privileges. Check Point confirmed exploitation against a handful of customers.

By SWI Community TeamJul 23, 2026Updated Aug 6, 2026

Check Point patched CVE-2026-16232 (CVSS 9.3), an authentication bypass in the SmartConsole login process affecting Security Management and Multi-Domain Management Server across versions R77.30 through R82.10. The flaw lets an unauthenticated remote attacker obtain a valid application login token and use it to authenticate with full administrative privileges, enough to modify security policies and configurations directly. Check Point confirmed active exploitation against a handful of customers, all with their Management Server's GUI client access exposed to the internet without IP restrictions, and has notified affected organizations directly. A jumbo hotfix shipped July 22, 2026, alongside patches for two related flaws, CVE-2026-62144 and CVE-2026-62145. CISA added the bug to its Known Exploited Vulnerabilities catalog, giving US federal agencies until July 25 to patch. A public proof of concept followed the patch on July 29.

Why it matters

This is a straightforward token theft bug wearing a management-console costume: the flaw doesn't steal a password, it hands an unauthenticated attacker the same token a real administrator would carry, no credential needed at any step. On a firewall management server, that token is administrative control over the policy that governs everything behind it.

The exposure requirement is the actionable part: this only bites organizations that left GUI client access to the Management Server reachable from the internet without IP restrictions. Confirm Trusted Clients is scoped, not just that the hotfix is applied, since a public PoC has existed since July 29.

Source: The Hacker News

Independent analysis. No vendor sponsorship.