HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 18:07 CET 37 dossiers MITRE ATT&CK mapping

Unattributed · exploited as a zero-day, confirmed by the vendorcritical

A token instead of a password: the Check Point SmartConsole flaw

Check Point has fixed an authentication flaw in SmartConsole, the console that administers its security gateways. CVE-2026-16232 lets an unauthenticated attacker obtain an application login token and use it to log in with full administrative privileges. The vendor confirms it was exploited as a zero-day against a small number of customers; CISA added it to the Known Exploited Vulnerabilities catalogue on 22 July, with a remediation deadline of the 25th. The sore point is where the flaw sits: in the panel that sets the firewall rules.

The console that commands the firewall

Some vulnerabilities matter for where they sit more than for how they work. CVE-2026-16232 is one of them. SmartConsole is the program Check Point administrators use to manage security gateways: they write the rules, decide what passes and what does not, push the configuration. It is the place from which the perimeter is commanded. A flaw that lets someone in without credentials is not a problem in just any application: it is a problem in the control panel of the defence itself.

The mechanism, described by the vendor in advisory sk185169, is a defect in the login process. An unauthenticated attacker with network visibility of the Management Server can obtain an application login token and present it as their own. The server accepts it and opens a session with full administrative privileges. From there, security policy and configuration can be altered — exactly the levers an attacker would want.

9.1
CVSS (NVD)
base score, version 3.1
unauthenticated
access prerequisite
only network reach to the Management Server is needed
22 Jul 2026
added to CISA KEV
remediation required by 25 July

A zero-day, not a hypothesis

What makes this story serious is that it is not a theoretical risk. Check Point states it is aware of active exploitation, while noting it affects a very small number of customers. CISA, by adding the flaw to its catalogue on the same day it was published, implicitly confirms the same picture: the vulnerability is weaponised and in use, not merely discovered. That is why the assigned remediation window is just three days.

The conditions for remote exploitation, per the advisory, are two and must be read together: the Management Server must be reachable over the internet, and the Trusted Clients — the list of addresses allowed to connect with the GUI — must be unrestricted. Where both are true, the door is open. Where the Management Server is closed to the outside or Trusted Clients are limited to trusted subnets, the surface shrinks considerably. That, not by chance, is also the immediate mitigation Check Point suggests alongside the patch.

What to do, with the version numbers

The fix ships through the Jumbo Hotfix Accumulators. According to the advisory, the correction is included in the Jumbo for R82.10 from Take 36 and in the Jumbo for R82 from Take 118. The containment measure worth applying regardless of patch status is to limit Trusted Clients (GUI clients) to trusted addresses and subnets, and not to expose the Management Server on the internet.

  1. 01
    Network to the Management Server
    the attacker must be able to reach it
  2. 02
    Login token obtained
    the authentication defect allows it without credentials
  3. 03
    SmartConsole session
    full administrator privileges, policy can be changed

The uncertainties, in plain view

A couple of things should be stated for what they are. The CVSS score is not entirely uniform: NVD assigns 9.1, while some sources report 9.3; the difference does not change the substance — this is a critical vulnerability — but we flag it because numbers are copied, not rounded. The MITRE ATT&CK identifiers here (T1190, T1078) are a reasoned mapping onto the described behaviour, not IDs published in the advisory: Check Point does not provide them, and we present them as a reading, not as an official datum. Finally, how many customers were actually hit is not quantified beyond the "very small number" the vendor states: that is reassurance, not an independently verifiable measure.

The central fact remains, and it is not arguable: for a few days, anyone running an exposed Check Point Management Server without client restrictions had, hanging over their head, a flaw that handed a stranger the keys to their own firewall. The patch exists. The priority is set by CISA: by 25 July.

More dossiers