CVE-2026-16232 — Check Point SmartConsole Improper Authentication Vulnerability

CVE-2026-16232

Check Point SmartConsole — Unauthenticated Login Token Theft Leads to Full Administrative Takeover

What is Check Point SmartConsole?

SmartConsole is the administrative GUI client used to manage Check Point Security Management Servers — the control plane behind Check Point's firewalls, VPNs, and gateway appliances deployed at enterprise network perimeters. An administrator with full SmartConsole access can reconfigure firewall policy, VPN settings, and gateway objects across an organization's entire security infrastructure, making the management server one of the highest-value targets in any Check Point deployment: compromising it doesn't just breach one system, it hands an attacker control over the security controls protecting everything behind it.

Overview

CVE-2026-16232 is an improper authentication vulnerability (CWE-287) that lets an unauthenticated, network-based attacker obtain a valid SmartConsole application login token and use it to authenticate to the Security Management Server with full administrative privileges — effectively a complete authentication bypass into the management control plane. Check Point confirmed exploitation against "a small number of customers" before publishing hotfixes and its advisory on July 22, 2026. CISA added the CVE to KEV the same day with one of the most compressed deadlines in this batch — just three days — reflecting the severity of an unauthenticated path to full administrative control over perimeter security infrastructure.

Affected Versions

Version Fixed in
R82.10 Jumbo Hotfix Take 36
R82 Jumbo Hotfix Take 118
R81.20 Jumbo Hotfix Take 158
R81.10, R81, R80.30, R80.20, R80.10, R80, R77.30 No fix available (end-of-life releases)

Organizations still running R81.10 or earlier have no vendor patch path and must rely on the mitigations below or upgrade to a supported version.

Technical Details

The flaw exists in the SmartConsole login process, where insufficient validation allows an attacker with network access to the Security Management Server to obtain an application login token without presenting valid credentials (CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, 9.1 Critical). Once obtained, the token authenticates the attacker as a full administrator, granting read and write access to firewall policy and configuration with no corresponding availability impact — i.e., the bug is about takeover and policy tampering, not denial of service. Check Point's public advisory is deliberately sparse on the exact token-retrieval mechanics, consistent with disclosure practice for a bug under active exploitation. Exploitation requires network reachability to the management server and depends on "Trusted Clients" (the IP allowlist governing which hosts may connect as GUI clients) not being restricted.

Discovery

No external researcher is publicly credited; Check Point's advisory language is consistent with internal discovery following detection of exploitation attempts against customer environments.

Exploitation Context

Check Point confirmed active exploitation affecting a small number of customers prior to releasing hotfixes, which is what drove the compressed three-day KEV remediation deadline — among the fastest in this batch of six. No specific threat actor has been publicly named, and CISA's KEV entry attributes the activity only to generic malicious cyber actors.

Remediation

  1. Apply the Jumbo Hotfix Take matching your version (see table above) immediately.
  2. If running an end-of-life version with no fix available (R81.10 and earlier), prioritize upgrading to a supported, patched release — there is no vendor mitigation for these branches.
  3. Restrict Trusted Clients to known-good management IPs: SmartConsole → Manage & Settings → Permissions & Administrators → Trusted Clients. This is the primary interim mitigation while patching and should remain in place afterward as defense in depth.
  4. Ensure the Security Management Server is never directly internet-facing — management interfaces should only be reachable from trusted internal networks or via VPN.
  5. Review SmartConsole login and administrator activity logs for unfamiliar administrator sessions, policy changes, or object modifications around and after the disclosure window, particularly any activity from IPs outside your known Trusted Clients list.

Key Details

PropertyValue
CVE ID CVE-2026-16232
Vendor / Product Check Point — SmartConsole
NVD Published2026-07-22
NVD Last Modified2026-07-23
CVSS 3.1 Score9.1
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
SeverityCRITICAL
CWE CWE-287 find similar ↗
CISA KEV Added2026-07-22
CISA KEV Deadline2026-07-25
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Required Action

CISA BOD 22-01 Deadline: 2026-07-25. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

DateEvent
2026-07-22Check Point publishes advisory sk185169 and ships hotfixes; CISA adds to KEV same day
2026-07-25CISA BOD 22-01 remediation deadline (3-day window)