A Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Management servers, then use it with full administrative privileges. Check Point confirmed exploitation against a handful of customers.
Check Point patched CVE-2026-16232 (CVSS 9.3), an authentication bypass in the SmartConsole login process affecting Security Management and Multi-Domain Management Server across versions R77.30 through R82.10. The flaw lets an unauthenticated remote attacker obtain a valid application login token and use it to authenticate with full administrative privileges, enough to modify security policies and configurations directly. Check Point confirmed active exploitation against a handful of customers, all with their Management Server's GUI client access exposed to the internet without IP restrictions, and has notified affected organizations directly. A jumbo hotfix shipped July 22, 2026, alongside patches for two related flaws, CVE-2026-62144 and CVE-2026-62145. CISA added the bug to its Known Exploited Vulnerabilities catalog, giving US federal agencies until July 25 to patch. A public proof of concept followed the patch on July 29.
Why it matters
This is a straightforward token theft bug wearing a management-console costume: the flaw doesn't steal a password, it hands an unauthenticated attacker the same token a real administrator would carry, no credential needed at any step. On a firewall management server, that token is administrative control over the policy that governs everything behind it.
The exposure requirement is the actionable part: this only bites organizations that left GUI client access to the Management Server reachable from the internet without IP restrictions. Confirm Trusted Clients is scoped, not just that the hotfix is applied, since a public PoC has existed since July 29.
Source: The Hacker News
Related on Start with Identity
- BlogA SharePoint JWT validation bug let unauthenticated attackers become any user, including admins
CVE-2026-55040 (CVSS 9.1) let a remote, unauthenticated attacker who knows a target's Active Directory SID or user principal name forge a valid session as that
- BlogForged OIDC tokens in SimpleHelp RMM handed out technician access to 1,000 exposed servers, no MFA required
CVE-2026-48558 lets an unauthenticated attacker forge OpenID Connect tokens against SimpleHelp remote-monitoring software configured for group login, gaining pr
- BlogA Zimbra XSS zero-day let a Russian espionage group read mailboxes and steal 2FA codes for months
NSA, CISA, and partner agencies detailed a year-long campaign against Zimbra Classic UI, tracked under several names including Void Blizzard and LAUNDRY BEAR, t
- CVECheck Point Security Gateway information disclosure of password hashes
An unauthenticated read on Check Point Security Gateways leaked password hashes, including those used for VPN and local admin. CISA KEV. May 2024. Hash disclosu
- CVEEntra ID Actor tokens enabled cross-tenant Global Admin
Undocumented Actor tokens plus an Azure AD Graph tenant-validation flaw let an attacker impersonate any user, including Global Admin, in every Entra ID tenant.
- VendorPerimeter 81 (Check Point)
strong_contender