Security
Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public
Image: Primary Check Point has confirmed active attacks on a critical SmartConsole authentication bypass. The flaw sits in its Security Management and Multi-Domain Management servers.
A working proof-of-concept is now public too. The bug is tracked as CVE-2026-16232 and carries a CVSS score of 9.3. It lets an unauthenticated attacker walk away with full administrator access to the management plane. Rapid7 published a technical breakdown of the bug on 22 July.
That was the same day Check Point shipped emergency Jumbo Hotfixes. Days later, Rapid7 researcher sfewer-r7 released a Python proof-of-concept on GitHub. It checks whether a given target is patched.
A confirmed in-the-wild attack plus a public exploit script is exactly the pattern defenders dread.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from latesthackingnews.com and reviewed by the T&B editorial agent team.
