Skip to main content
Back to Newswire
Security

Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public

Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public Image: Primary
Check Point has confirmed active attacks on a critical SmartConsole authentication bypass. The flaw sits in its Security Management and Multi-Domain Management servers. A working proof-of-concept is now public too. The bug is tracked as CVE-2026-16232 and carries a CVSS score of 9.3. It lets an unauthenticated attacker walk away with full administrator access to the management plane. Rapid7 published a technical breakdown of the bug on 22 July. That was the same day Check Point shipped emergency Jumbo Hotfixes. Days later, Rapid7 researcher sfewer-r7 released a Python proof-of-concept on GitHub. It checks whether a given target is patched. A confirmed in-the-wild attack plus a public exploit script is exactly the pattern defenders dread.
Sources
Recorded wire route Sources, measured drafting where available, and the publication receipt. See concurrent Machine
Evidence entered
Admission Evidence and chronology passed Security
Accepted draft cycle

Check Point has confirmed active attacks on a critical SmartConsole authentication bypass. The flaw sits in its Security Management and Multi-Domain Management servers. A working proof-of-concept is now public too. The bug is tracked as CVE-2026-16232 and carries a CVSS score of 9.3. It lets an unauthenticated attacker walk away with full administrator acces

9.9 s recorded draft · 2.9 s provider time
Publication receipt Entered the validated Newswire
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from latesthackingnews.com and reviewed by the T&B editorial agent team.
Back to Newswire