Check Point SmartConsole Zero-Day Vulnerability Exploited in the Wild, Official Emergency Fix Released
Check Point Software issued a security advisory on Wednesday, disclosing a critical authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole login process that is being actively exploited, affecting a small number of customers. The vulnerability allows attackers to gain full administrative access after obtaining an application login token, enabling them to modify security policies and configurations, with a severity score of 9.1/10. The official jumbo hotfix has been released to address this vulnerability and two other security issues, and the U.S. CISA has also added it to its Known Exploited Vulnerabilities catalog, requiring federal agencies to complete mitigation within a specified timeframe.

Check Point Software issued a security advisory on Wednesday, confirming an actively exploited critical vulnerability in its SmartConsole login process, affecting a small number of customers. The advisory stated that attackers could exploit this authentication bypass flaw to gain full administrative privileges after obtaining an application login token, thereby modifying security policies and configurations.
The vulnerability is tracked as CVE-2026-16232, with a severity score of 9.1 out of 10. Check Point stated in the advisory that it released a jumbo hotfix on Wednesday to address multiple security issues in its firewall and management products.
A blog post by Rapid7 on Thursday highlighted that this type of vulnerability is particularly concerning because it grants attackers the ability to make multiple changes. Rapid7 noted that remote attackers could "modify administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring functions."
"In simple terms, this vulnerability targets the system that tells the firewall what to trust," said Douglas McKee, Director of Vulnerability Intelligence at Rapid7.
According to Rapid7, the vulnerability was discovered by Check Point during routine internal reviews. Remote exploitation is only possible under the following conditions: there is internet access to the management server's IP address in the environment, and trusted clients are not restricted.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this SmartConsole vulnerability to its Known Exploited Vulnerabilities catalog on Wednesday. The agency set a Saturday deadline for Federal Civilian Executive Branch (FCEB) agencies to complete environmental mitigation measures.
The released jumbo hotfix also addresses two other security issues:CVE-2026-62144(a critical authentication bypass vulnerability in Check Point Security Management) and CVE-2026-62145(a high-severity vulnerability in Check Point Gaia Portal).