Check Point has confirmed that CVE-2026-16232, an authentication bypass in its SmartConsole management interface, is being actively exploited. The flaw lets an unauthenticated attacker obtain an application login token and use it to sign in to SmartConsole with full administrative privileges over a Security Management Server or Multi-Domain Security Management Server, then change security policy and configuration. Check Point says exploitation so far has affected “a very small number of customers.” CISA added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until July 25 to patch under Binding Operational Directive 26-04.
The bug matters beyond its patch count because of what SmartConsole controls. It is not a single firewall or endpoint agent; it is the administrative console that pushes policy to every gateway a Security Management Server oversees. An attacker who reaches full admin access through the console inherits the ability to rewrite rules across the entire managed estate at once, not just compromise a single device, which is a materially larger blast radius than most appliance bugs carry.
That distinction is the real signal here. CyberTech has also covered Qilin’s exploitation of a GlobalProtect authentication bypass this month, another case where the entry point was the software security teams use to manage remote access, not an unpatched application server. CISA’s emergency patch list is increasingly populated by the management and console layer that defenders trust implicitly, which means that layer now needs the same scrutiny, segmentation, and access restriction long reserved for the perimeter it protects. Check Point recommends restricting SmartConsole’s Trusted Clients to specific IP ranges rather than leaving access open to any client, in addition to applying the available hotfixes.