Check Point has disclosed and patched a critical zero-day vulnerability, CVE-2026-16232, affecting its SmartConsole management platform. The flaw is an authentication bypass vulnerability that enables unauthenticated remote attackers to obtain a valid application login token and authenticate with administrator-level privileges under specific conditions. Check Point confirmed that the vulnerability is being actively exploited and has impacted a limited number of customers.
Successful exploitation could allow threat actors to gain administrative access to vulnerable Security Management Servers, modify security policies, alter configurations, and potentially weaken an organization's overall security posture.
In response to active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) Catalog, urging organisations to prioritise remediation efforts.
CVE-2026-16232 is an authentication bypass vulnerability within Check Point SmartConsole that allows an attacker to obtain an application authentication token without valid credentials. The token can then be leveraged to authenticate with administrative privileges against affected management infrastructure.
Indicators of Compromise (IoCs)
Check Point recommends reviewing audit logs for evidence of unauthorized token-based authentication activity.
Log Review
Search SmartConsole Audit Logs for:
Authentication method: application token
Check Point also advises investigating activity associated with the following IP addresses:
Recommended SmartConsole query:
(src:151.241.99.207 OR dst:151.241.99.207 OR
src:151.241.99.233 OR dst:151.241.99.233 OR
src:158.62.198.182 OR dst:158.62.198.182 OR
src:192.142.10.99 OR dst:192.142.10.99 OR
src:139.28.37.250 OR dst:139.28.37.250)
Organizations identifying suspicious authentication events should immediately initiate incident response procedures and conduct a full review of policy changes made through SmartConsole.
Immediate Actions
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.