Security & Threat Intelligence · 25.07.2026, 15:30 UTC
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
| Schweregrad | critical aktiv ausgenutzt (KEV) |
|---|---|
| CVSS | 9.1 |
| CVE | ↗ ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Rapid7 Blog ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad kritisch (CVSS 9.1). Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2024-24919, CVE-2026-16232, CVE-2026-50751, CVE-2026-62144, CVE-2026-62145. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
OverviewOn July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login process classified as improper authentication (CWE-287). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote exploitation requires network access to the Management Server IP address in environments that do not restrict Trusted Clients. On the same day as the advisory, CVE-2026-16232 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities (KEV), with a remediation due date of July 25, 2026, giving organizations only three days to respond.The advisory addresses three vulnerabilities in total:CVECVSSDescriptionAffected ProductsExploitation StatusCVE-2026-16232Vendor: 9.3 (Critical)CISA: 9.1 (Critical)Authentication bypass via SmartConsole application tokenSecurity Management, Multi-Domain ManagementExploited in the wildCVE-2026-62144Vendor: 9.3 (Critical)CISA: 9.1 (Critical)Management authentication bypass and privilege escalationSecurity …