CVE-2026-16232

Confirmed PUBLISHED

Authentication Bypass in the SmartConsole Login Process Using an Application Token

checkpoint · Quantum Security Management, Multi-Domain Security Management

7 hours faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.3 Critical

At a Glance

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

cisa
CVE Published
Jul 22, 2026
Exploitation Reported
Jul 22, 2026
CVSS
9.3 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
checkpoint
Quantum Security Management

R82.10 with Jumbo Hotfix Take 36 or below

Affected
checkpoint
Quantum Security Management

R82 with Jumbo Hotfix Take 118 or below

Affected
checkpoint
Quantum Security Management

R81.20 with Jumbo Hotfix Take 158 or below

Affected
checkpoint
Quantum Security Management

R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30

Affected
checkpoint
Multi-Domain Security Management

R82.10 with Jumbo Hotfix Take 36 or below

Affected
checkpoint
Multi-Domain Security Management

R82 with Jumbo Hotfix Take 118 or below

Affected
checkpoint
Multi-Domain Security Management

R81.20 with Jumbo Hotfix Take 158 or below

Affected
checkpoint
Multi-Domain Security Management

R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.