Critical Check Point SmartConsole Authentication Bypass Vulnerability Exposed with Public PoC
A critical authentication bypass vulnerability (CVE-2026-16232) in Check Point SmartConsole allows unauthenticated attackers to gain administrative privileges by exploiting a broken trust boundary in the authentication process. Rapid7 has released a proof-of-concept tool to validate exploitation, while Check Point advises immediate application of jumbo hotfixes to remediate the flaw.
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that
*** END OF TRANSMISSION ***