Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
A critical security flaw in Check Point's SmartConsole allows unauthenticated attackers to gain full administrative privileges, and a proof-of-concept has been released. This vulnerability has been actively exploited in the wild, targeting Check Point customers.
A critical security vulnerability in Check Point’s SmartConsole allows attackers to bypass authentication and gain full administrative access to the Security Management Server and Multi-Domain Security Management Server. Researchers at Rapid7 have identified this flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), which enables an unauthenticated attacker to obtain an application login token and use it to log in with full administrator privileges. The root cause is a ‘broken trust boundary’ in the application authentication path, allowing an attacker to read the management server’s own Secure Internal Communication (SIC) distinguished name (DN) during unauthenticated bootstrap communication and then authenticate as a remote application. Successful exploitation requires network access to the Management Server and a configuration that does not restrict Trusted Clients. Check Point has confirmed that a small number of customers are currently being targeted by this zero-day exploit. The vulnerability has been addressed with a Jumbo Hotfix released on July 22, 2026. Rapid7 has released a Python proof-of-concept to demonstrate the exploit and verify whether a target system is vulnerable or patched.
