Security advisories

PoC Exploit Code Released for Check Point SmartConsole Zero-Day Vulnerability (CVE-2026-16232)

July 29, 2026

4 MINS READ

THE THREAT

On July 28th, 2026, Rapid7 Labs published technical details and Proof-of-Concept (PoC) exploit code for CVE-2026-16232 (CVSS: 9.1), a critical authentication bypass vulnerability in the SmartConsole login process impacting Check Point's Security Management Server and Multi-Domain Security Management Server (MDS). Exploitation of the vulnerability can allow an unauthenticated attacker to obtain an application login token and use it to authenticate with full administrative privileges, which can enable the modification of security policies and configurations.

Within Check Point's initial disclosure of CVE-2026-16232, they confirmed that patches were available, and that exploitation had been observed, impacting a "very small number of customers". Given that PoC exploit code for the vulnerability is now available, organizations should ensure that the relevant patches are applied immediately.

What we're doing about it

What you should do about it

Additional information

Check Point initially disclosed CVE-2026-16232 on July 22nd, 2026, where they confirmed that limited exploitation had been observed, but provided no additional details on the identified attacks. Check Point indicated that exploitation of the vulnerability requires attackers to have Internet access to the Management Server IP address, and no restrictions on Trusted Clients (GUI clients). Successful exploitation of CVE-2026-16232 can grant attackers full administrative privileges, allowing for the modification of security policies and configurations. Following Check Point's disclosure, CISA added CVE-2026-16232 to it's Known Exploited Vulnerabilities (KEV) catalog on July 22nd.

Within Rapid7's testing of the flaw, they note that the settings required for exploitation were default configurations. The root cause of CVE-2026-16232 was identified as a broken trust boundary in the application authentication path, which allows a vulnerable server to accept attacker-supplied Secure Internal Communication (SIC) distinguished name (DN) as a valid application identity without verifying it against the authenticated peer certificate. This is used to obtain an application token, which requests a Smart Console Single Sign-On (SSO) ticket, granting access. Along with their report, Rapid7 published PoC exploit code, which can be leveraged to exploit the flaw. The release of PoC exploit code for a vulnerability is often a early warning sign for widespread exploitation, as it lowers the barrier for threat actors to operationalize within attacks.

Given reports of exploitation and release of PoC, eSentire's Threat Intelligence team assesses with medium confidence that widespread exploitation of CVE-2026-16232 will be seen in the near term. As such, impacted organizations should ensure that relevant patches are applied, access to the Management Server is restricted to trusted IP addresses, and follow Check Point's Hardening Best Practices guide to reduce risk.

Affected Products and Versions
Security Management Server and Multi-Domain Security Management Server R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
Indicators of Compromise (IOCs) Identified by Check Point
151[.]241[.]99[.]207 Attacker IP Address
151[.]241[.]99[.]233 Attacker IP Address
158[.]62[.]198[.]182 Attacker IP Address
192[.]142[.]10[.]99 Attacker IP Address
139[.]28[.]37[.]250 Attacker IP Address
Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories