# Check Point warns of SmartConsole zero-day exploited in attacks

_Thursday, July 23, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Check Point warns of SmartConsole zero-day exploited in attacks — Primary](https://www.bleepstatic.com/content/hl-images/2026/07/23/Check-Point-headpic.jpg)

Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the SmartConsole graphical user interface admin panel, the company said in a Sunday advisory. Tracked as CVE-2026-16232, the authentication bypass vulnerability allows unauthenticated attackers to obtain an application login token to authenticate with administrator privileges.

Successful exploitation allows attackers to modify security policies and configurations on vulnerable Security Management Servers or Multi-Domain Security Management Servers. Check Point said remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients, adding that it is aware the vulnerability is being exploited and has affected a very small number of customers.

Admins unable to upgrade immediately are advised to follow the Check Point Hardening Best Practices Guide, limit Trusted Clients to trusted IP addresses, and ensure management access is blocked for non-authorized IPs. On Wednesday, the Cybersecurity and Infrastructure Security Agency added the flaw to its catalog of known exploited vulnerabilities, ordering U.S. federal agencies to patch by Saturday, July 25, under Binding Operational Directive 26-04. CISA urged all organizations to prioritize patching to block incoming attacks.

## Sources

- [Bleeping Computer](https://www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/)

---
Canonical: https://techandbusiness.org/newswire/K8mMH6M4cSnGMuVnE4O9tT
Retrieved: 2026-07-24T03:51:40.439Z
Publisher: Tech & Business (techandbusiness.org)
