Actively exploited Check Point SmartConsole authentication bypass (CVE-2026-16232)
Check Point has disclosed and patched a critical zero-day vulnerability, CVE-2026-16232, affecting its SmartConsole management platform. The flaw is an authentication bypass vulnerability that enables unauthenticated remote attackers to obtain a valid application login token and authenticate with administrator-level privileges under specific conditions. Check Point confirmed that the vulnerability is being actively exploited and has impacted a limited number of customers.