# Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public

_Published Monday, August 3, 2026 at 10:17 AM EDT · Security · Latest · Tier 2 — Notable_

![Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public — Primary](https://latesthackingnews.com/wp-content/uploads/2026/07/it-administrator-reviewing-multiple-monitors-in-a-network-op.jpg)

Check Point has confirmed active attacks on a critical SmartConsole authentication bypass. The flaw sits in its Security Management and Multi-Domain Management servers.

A working proof-of-concept is now public too. The bug is tracked as CVE-2026-16232 and carries a CVSS score of 9.3. It lets an unauthenticated attacker walk away with full administrator access to the management plane. Rapid7 published a technical breakdown of the bug on 22 July.

That was the same day Check Point shipped emergency Jumbo Hotfixes. Days later, Rapid7 researcher sfewer-r7 released a Python proof-of-concept on GitHub. It checks whether a given target is patched.

A confirmed in-the-wild attack plus a public exploit script is exactly the pattern defenders dread.

## Sources

- [latesthackingnews.com](https://latesthackingnews.com/2026/08/02/smartconsole-authentication-bypass/)

---
Canonical: https://techandbusiness.org/newswire/w644qEk_8Tm4ZlRdfr-QnK
Published: 2026-08-03T14:17:02.638Z
Story chronology: 2026-08-02T12:00:00.000Z
Retrieved: 2026-09-17T21:25:53.068Z
Publisher: Tech & Business (techandbusiness.org)
