Check Point warns of SmartConsole zero-day exploited in attacks

Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel.

Tracked as CVE-2026-16232, this authentication bypass vulnerability allows unauthenticated attackers to obtain an application login token that can be used to authenticate with administrator privileges.

After gaining access to a vulnerable Security Management Server or Multi-Domain Security Management Server (MDS), attackers can change the security configuration and security policy.

Check Point added that successful exploitation requires no restrictions on Trusted Clients (GUI clients) and the Management Server IP to be exposed to remote access via the Internet.

“Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients,” the company said in a Sunday advisory.

“Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.”

Admins who can’t immediately upgrade to a patched version are advised to follow the Check Point Hardening Best Practices Guide, limit Trusted Clients to trusted IP addresses/subnets, and ensure that management access is blocked for non-authorized IP addresses.

To verify if a SmartConsole instance has been compromised, admins have to search for the query “Authentication method: application token” in SmartConsole under Logs & Monitor / Logs & Events > Audit Logs View after running the following SmartConsole query:

(src:151.241.99.207 OR dst:151.241.99.207 OR src:151.241.99.233 OR dst:151.241.99.233 OR src:158.62.198.182 OR dst:158.62.198.182 OR src:192.142.10.99 OR dst:192.142.10.99 OR src:139.28.37.250 OR dst:139.28.37.250) On Wednesday, CISA also added the flaw to its catalog of known exploited vulnerabilities, ordering U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.

“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency warned.

“Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.”

While BOD 26-04 applies only to U.S. government agencies, CISA urged all organizations to prioritize patching the CVE-2026-16232 vulnerability to block incoming attacks.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Google fixes one actively exploited Android zero-day, 124 flaws

CISA orders urgent action on actively exploited Langflow RCE flaw

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

CISA warns of actively exploited RCE flaws in Joomla extensions

Hackers exploit critical auth bypass in Gitea Docker image

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Hugging Face warns an autonomous AI agent hacked its network

Critical ServiceNow code execution flaw now exploited in attacks

See how Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Read the case study.

Overdue a password health-check? Audit your Active Directory for free

Privacy by policy or privacy by architecture? See how age checks work when the face never leaves the device.

Calculate what you’d save by replacing your MDR.

Do you have what it takes to challenge DARKROOM? Signup for an exclusive DEFCON CTF!

AI agents can speed up ransomware attacks. See how Acronis helps reduce the risk.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.