# Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public

_Sunday, August 2, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public — Primary](https://latesthackingnews.com/wp-content/uploads/2026/07/it-administrator-reviewing-multiple-monitors-in-a-network-op.jpg)

Check Point has confirmed active attacks on a critical SmartConsole authentication bypass. The flaw sits in its Security Management and Multi-Domain Management servers.

A working proof-of-concept is now public too. The bug is tracked as CVE-2026-16232 and carries a CVSS score of 9.3. It lets an unauthenticated attacker walk away with full administrator access to the management plane. Rapid7 published a technical breakdown of the bug on 22 July.

That was the same day Check Point shipped emergency Jumbo Hotfixes. Days later, Rapid7 researcher sfewer-r7 released a Python proof-of-concept on GitHub. It checks whether a given target is patched.

A confirmed in-the-wild attack plus a public exploit script is exactly the pattern defenders dread.

## Sources

- [latesthackingnews.com](https://latesthackingnews.com/2026/08/02/smartconsole-authentication-bypass/)

---
Canonical: https://techandbusiness.org/newswire/w644qEk_8Tm4ZlRdfr-QnK
Retrieved: 2026-08-03T17:44:39.348Z
Publisher: Tech & Business (techandbusiness.org)
