Bottom line: A critical vulnerability in Check Point’s management server enables unauthenticated access with full admin privileges, granting control over all managed gateways; the exploit has been known in attack attempts since April.
Check Point confirms active exploits of a critical vulnerability (CVE-2026-16232, CVSS 9.3) in SmartConsole, which allows unauthenticated attackers to obtain full admin rights on the central management console. The company has already issued a patch and notified ten affected customers.
The vulnerability CVE-2026-16232 affects the login system of SmartConsole on the Security Management Server. An unauthenticated attacker can obtain an application login token and use it to log in with full admin privileges. From this position, the attacker can manipulate security policy and security configuration, establish new VPN connections, and disable logging.
Critical for assessing the vulnerability is its position in the network stack: while access to a single gateway only compromises one component of the infrastructure, access to the management server means control over all underlying gateways. Check Point recommends restricting access to trusted IP addresses and subnets – an approach that, however, presents practical challenges in modern network environments.
Check Point discovered the vulnerability on Sunday, notified customers the same day, and provided the patch within 72 hours. Upon reviewing older logs, attack attempts were evident starting in April. The fact that only ten organizations were affected over a three-month period suggests that it is difficult for attackers to find vulnerable systems – most customers are already using secure configurations.
Restricting management access to trusted network segments (VPN pools, management VLANs, or jump hosts) is technically more practical than managing IP allowlists for dynamically assigned DHCP addresses. However, in practice it is often found that IT teams resort to less secure settings when restrictions are too strict, in order to reduce administrative overhead.
Source: www.csoonline.com · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.