← Back to Feed
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
CVE-2026-16232
July 29, 2026 · The Hacker News · Severity: CRITICAL
Rapid7 released technical details about CVE-2026-16232, a critical authentication bypass (CVSS 9.3) in Check Point Security Management Server that allows unauthenticated remote attackers to obtain login tokens with full administrative privileges. The flaw has been actively exploited as a zero-day in the wild, with Check Point confirming a handful of targeted customers.
Key Takeaways
- CVE-2026-16232 is a CVSS 9.3 authentication bypass in the Check Point SmartConsole login process
- Unauthenticated remote attackers can obtain application login tokens granting full admin privileges
- Exploitation requires network access to the Management Server and a configuration not restricting Trusted Clients