Check Point warns of SmartConsole zero-day exploited in attacks
Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. The vulnerability, tracked as CVE-2026-16232, allows unauthenticated attackers to obtain an application login token that can be…
Intelligence analysis by Llama

Check Point has patched a zero-day flaw in SmartConsole that allows attackers to gain administrator privileges. The company is urging admins to upgrade to a patched version and follow hardening best practices to prevent exploitation.
Imagine you have a super powerful tool that can control everything in your network. But, someone found a way to get into that tool without a password. That's what happened with Check Point's SmartConsole. The company is urging admins to update their tool to prevent bad guys from getting in.
Analysis
A Critical Vulnerability in SmartConsole
Check Point Software has recently addressed a critical zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. The vulnerability, tracked as CVE-2026-16232, allows unauthenticated attackers to obtain an application login token that can be used to authenticate with administrator privileges.
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. The Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its catalog of known exploited vulnerabilities and has ordered U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.
While BOD 26-04 applies only to U.S. government agencies, CISA urged all organizations to prioritize patching the CVE-2026-16232 vulnerability to block incoming attacks. In June, CISA ordered federal agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against another authentication bypass vulnerability (CVE-2026-50751) that was exploited in zero-day attacks by the Qilin ransomware gang.
The Impact of the Vulnerability
The CVE-2026-16232 vulnerability allows attackers to gain administrator privileges, which can be used to modify security policies and security configurations. Successful exploitation requires no restrictions on Trusted Clients (GUI clients) and the Management Server IP to be exposed to remote access via the Internet.
Admins who cannot immediately upgrade to a patched version are advised to follow the Check Point Hardening Best Practices Guide, limit Trusted Clients to trusted IP addresses/subnets, and ensure that management access is blocked for non-authorized IP addresses.
Verifying Compromise
To verify if a SmartConsole instance has been compromised, admins have to search for the query "Authentication method: application token" in SmartConsole under Logs & Monitor / Logs & Events > Audit Logs View after running the following SmartConsole query:
(src:151.241.99.207 OR dst:151.241.99.207 OR src:151.241.99.233 OR dst:151.241.99.233 OR src:158.62.198.182 OR dst:158.62.198.182 OR src:192.142.10.99 OR dst:192.142.10.99 OR src:139.28.37.250 OR dst:139.28.37.250)
Conclusion
The CVE-2026-16232 vulnerability is a critical issue that requires immediate attention from admins. Patching vulnerable SmartConsole instances and following hardening best practices are essential to prevent further attacks.
Key points
- Check Point Software has patched a zero-day flaw in SmartConsole that allows attackers to gain administrator privileges.
- The vulnerability, tracked as CVE-2026-16232, allows unauthenticated attackers to obtain an application login token that can be used to authenticate with administrator privileges.
- CISA has ordered U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.
- Admins who cannot immediately upgrade to a patched version are advised to follow the Check Point Hardening Best Practices Guide and limit Trusted Clients to trusted IP addresses/subnets.
If admins patch their SmartConsole instances and follow hardening best practices, they can prevent further attacks and keep their networks secure.
If admins fail to patch their SmartConsole instances, they risk being exploited by attackers, which can lead to significant security risks and potential data breaches.



