Check Point has disclosed and patched a critical zero-day vulnerability, CVE-2026-16232, affecting its SmartConsole management platform. The flaw is an authentication bypass vulnerability that enables unauthenticated remote attackers to obtain a valid application login token and authenticate with administrator-level privileges under specific conditions. Check Point confirmed that the vulnerability is being actively exploited and has impacted a limited number of customers.
Successful exploitation could allow threat actors to gain administrative access to vulnerable Security Management Servers, modify security policies, alter configurations, and potentially weaken an organization's overall security posture.
In response to active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) Catalog, urging organisations to prioritise remediation efforts.
Technical Details
CVE-2026-16232 is an authentication bypass vulnerability within Check Point SmartConsole that allows an attacker to obtain an application authentication token without valid credentials. The token can then be leveraged to authenticate with administrative privileges against affected management infrastructure.
- Exploitation Requirements
- Exploitation is possible when:
- The Check Point Management Server is accessible from the Internet.
- Trusted Client restrictions are not properly configured.
- Management access is permitted from untrusted or unrestricted source IP addresses.
- Exploitation is possible when:
Indicators of Compromise (IoCs)
Check Point recommends reviewing audit logs for evidence of unauthorized token-based authentication activity.
Log Review
Search SmartConsole Audit Logs for:
-
Authentication method: application token
Check Point also advises investigating activity associated with the following IP addresses:
- 151.241.99.207
- 151.241.99.233
- 158.62.198.182
- 192.142.10.99
- 139.28.37.250
Recommended SmartConsole query:
(src:151.241.99.207 OR dst:151.241.99.207 OR
src:151.241.99.233 OR dst:151.241.99.233 OR
src:158.62.198.182 OR dst:158.62.198.182 OR
src:192.142.10.99 OR dst:192.142.10.99 OR
src:139.28.37.250 OR dst:139.28.37.250)
Organizations identifying suspicious authentication events should immediately initiate incident response procedures and conduct a full review of policy changes made through SmartConsole.
Mitigations and Remediations
Immediate Actions
- Apply Check Point's security updates immediately to all affected SmartConsole deployments.
- Restrict Trusted Clients to authorized management workstations and approved subnets only.
- Remove Internet exposure of Security Management Servers wherever possible.
- Implement management-plane access controls, allowing administration only from dedicated management networks, VPNs, or approved source IP ranges.
- Review audit logs for application token authentication events and unexpected administrative actions.
- Follow the latest Check Point Hardening Best Practices Guide to strengthen management infrastructure. - https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/CP_Check_Point_Gateway_and_Management_Hardening.pdf
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.
