Check Point Hole Grants Unauthenticated Attackers Full SmartConsole Admin Privileges
10 Articles
10 Articles
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3. In its security alert, Check Point described the bug as one allowing an unauthenticated attacker to “obtain an application login token and use it to login via SmartConsole with fu…
Check Point has published an emergency update to correct a set of critical vulnerabilities that affect its management servers, including CVE-2026-16232, already explored in real attacks. The problem puts organizations that maintain administrative interfaces exposed to the internet at risk, allowing invaders to take control of the environment responsible for managing network security policies. The alert is especially relevant for SysAdmins, netwo…
Can Check Point Software (NASDAQ:CHKP) Overcome Growth Concerns?
Check Point Software combines dependable earnings broad cybersecurity capabilities and disciplined operations while competitive pressure and moderate growth keep attention focused on cloud adoption and future execution ...
Multiple vulnerabilities have been discovered in Check Point products. They allow an attacker to cause increased privileges and circumvention of security policy. Check Point indicates that CVE-2026-16232 vulnerability is actively exploited. See online: https://www.cert.ssi.gouv.fr/avis/C...
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security …
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium



