#SmartConsole
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
www.bleepingcomputer.com
July 23, 2026 at 8:13 AM
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
thehackernews.com
July 29, 2026 at 9:18 AM
Imagine having a "modern" NGFW that by itself is useless unless you also run a virtual appliance (SmartCenter) to manage and configure it? Also you can only configure it by connecting to the appliance with a Windows app (SmartConsole). Absolutely fucking trash.
August 11, 2026 at 10:36 AM
Check Point patches a zero-day in its SmartConsole panel

support.checkpoint.com/results/sk/s...
July 22, 2026 at 11:06 PM
Check Point released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in Security Management Server products being exploited in the wild, enabling unauthenticated script execution. #CheckPoint #CVE202693616 #SmartConsole
Check Point Warns Of Management Server Zero-day Exploited In Attacks
Check Point Software released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in Security Management Server products that allowed unauthenticated attackers to upload and run arbitrary scripts. The company said the issue is being exploited in the wild and urged customers to patch immediately or apply temporary mitigations while checking for signs of compromise. #CheckPoint #CVE-2026-93616 #SecurityManagementServer #SmartConsole
www.hendryadrian.com
September 22, 2026 at 7:45 PM
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds SharePoint and Check Point vulnerabilities to its Known Exploited Vulnerabilities catalog..
securityaffairs.com
July 23, 2026 at 9:43 PM
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
thehackernews.com
July 23, 2026 at 8:33 AM
Old: 2 x SG6400, 2 x SG5200 and a SmartConsole VM. Check Point license centre said that is a $106k install base, yearly renewals were $80k.

New: 2 x FGT 400F, 2 x FGT 80F and a FortiAnalyzer VM with 50GB/day license. $50k to procure with 1-year FortCare Premium support, yearly renewal ~$15k.
May 7, 2024 at 12:01 PM
Check Point patches actively exploited SmartConsole authentication bypass flaw
Check Point patches actively exploited SmartConsole authentication bypass flaw - Security Affairs
Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited.
securityaffairs.com
July 23, 2026 at 9:18 AM
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
thehackernews.com/2026/07/chec...
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point patches actively exploited CVE-2026-16232, a SmartConsole auth bypass that grants full admin access on exposed management servers.
thehackernews.com
July 24, 2026 at 11:13 AM
Check Point's SmartConsole Flaw: Critical Yet Vague Exploitation Claims #CyberSecurity #InformationSecurity #CheckPoint
Check Point's SmartConsole Flaw: Critical Yet Vague Exploitation Claims
Check Point's SmartConsole flaw bypasses authentication, but details remain vague and the evidence weak. Here's a skeptical look at the situation.
cybernewsroom.xyz
July 23, 2026 at 2:38 PM
Check Point patched a zero-day that let attackers skip login for admin access, prompting a CISA patch order. This is a textbook case of and auth-bypass vulnerability moving from disclosure to a federal patch mandate in days, and the incident-response and risk triage MSIT prepares practitioners for.
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
www.bleepingcomputer.com
July 27, 2026 at 3:24 PM
Weitere Sicherheitslücken in SharePoint stehen unter Beschuss. Auch Check Point SmartConsole wird derzeit attackiert. #Security
Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke
Weitere Sicherheitslücken in SharePoint stehen unter Beschuss. Auch Check Point SmartConsole wird derzeit attackiert.
www.heise.de
July 23, 2026 at 7:17 AM
🛡️ Revue cyber du 18/09. 🔥 Check Point : RCE activement exploitée — repérer « Administrator failed to log in: Username too long » dans SmartConsole. https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1193/
September 18, 2026 at 5:56 AM
Zero-day flaw in Check Point SmartConsole is under exploitation www.cybersecuritydive.com/news/zero-da...
Zero-day flaw in Check Point SmartConsole is under exploitation
Researchers warned the vulnerability offers an attacker the ability to make key changes to security configurations.
www.cybersecuritydive.com
July 25, 2026 at 9:42 AM
Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released
Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released
A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available. Tracked as CVE-2026-16232, the flaw affects Security Management Server and Multi-Domain Security Management Server (MDS) and can give an unauthenticated attacker full administrator access through the SmartConsole management interface. On July 22, 2026, Check Point published a security advisory detailing the issue, while Rapid7 Labs confirmed exploitation in the wild and released a public proof-of-concept to help defenders validate exposure. CVE-2026-16232 sits in the SmartConsole login path. An attacker with network reach to the Management Server can obtain an application login token, use it to authenticate through SmartConsole with full administrator privileges, and then change security policy or configuration. Check Point Zero-Day PoC Released Successful abuse depends on network access to the management plane and a Trusted Clients setup that does not tightly restrict GUI clients, a condition Rapid7 observed as default in testing. Because the bug was already under attack at disclosure, organizations running exposed management servers face elevated risk until they patch and harden access. According to Rapid7’s analysis, the root cause is a broken trust boundary in application authentication. A vulnerable server accepts an attacker-supplied Secure Internal Communication (SIC) distinguished name as the identity of a remote application instead of binding that identity to the authenticated remote peer certificate returned by the platform. Attack Chain (Source: Rapid7) An attacker can learn the management server’s own SIC DN during unauthenticated bootstrap traffic, replay it in a forged application certificate bind, receive an application token, and then request a SmartConsole single sign-on ticket from the legacy management service. That ticket is redeemed over the newer CPM SOAP API, producing a full SmartConsole session with administrator rights. SmartConsole management traffic spans two generations of services. The legacy FWM/CPMI service on TCP 18190 handles SIC-based trust and older FwSet-style exchanges, while the CPM/DLE stack on TCP 19009 exposes SOAP operations under /cpmws/ and relies on session headers after login. The exploit chains both: it abuses FWM/CPMI to claim an application identity and mint a token, then uses that session to generate and redeem a SmartConsole SSO ticket. Once redeemed, the attacker holds session identifiers that support privileged operations, including reading server details and enumerating administrator accounts. Audit logs may show “Authentication method: application token,” which defenders can treat as a useful indicator of compromise. Rapid7 reproduced the issue on affected R81.20 and R82.10 builds and published a PoC script on GitHub that checks whether a target is vulnerable or patched. Vendor fixes block the attack path by ensuring remote application authentication uses the certificate-bound peer DN rather than an untrusted caller-supplied name, and by rejecting mismatches or missing SIC identities. On patched systems, the forged bind fails, and the PoC reports the host as not vulnerable. Organizations should apply Check Point’s recommended Jumbo Hotfix updates immediately, restrict management-plane access to trusted networks and clients, and review audit logs for suspicious application-token authentications.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released appeared first on Cyber Security News .
cybersecuritynews.com
July 29, 2026 at 9:52 AM
Friday’s fuck up - This Time - Great CheckPoint - Check Point SmartConsole Authentication Bypass (CVE-2026-16232)

Authentication bypass via the SmartConsole login process using an application token.
Blog: www.rapid7.com/blog/post/ra... #checkpoint #vulnerable #bypass #critacal #cve-2026-16232
Rapid7
Root cause technical analysis of CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Check Point Security Management Server and Multi-Domain Security Management Server...
www.rapid7.com
July 31, 2026 at 2:48 PM
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
July 29, 2026 at 9:08 AM
One oversized username and Check Point's management server hands over root, pre-auth. https://intel.threadlinqs.com/threat/TL-2026-2557 #ThreatIntel #CVE_2026_91843 #SmartConsole #CheckPoint
September 18, 2026 at 5:02 AM
🌑 HADAL · actively exploited critical
CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote …
CVSS 9.1 · EPSS 70.0% · CISA KEV · 0day
https://beta.vulnsea.com/cve/CVE-2026-16232

#CVE #infosec #cybersecurity #threatintel
CVE-2026-16232 — An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…
beta.vulnsea.com
August 2, 2026 at 9:00 AM
You can now share your thoughts on vulnerability CVE-2024-24915 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2024-24915

checkpoint - Check Point SmartConsole

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2024-24915
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
June 29, 2025 at 12:25 PM
You can now share your thoughts on vulnerability CVE-2024-24916 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2024-24916

checkpoint - Check Point SmartConsole

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2024-24916
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
June 19, 2025 at 1:44 PM
A critical authentication bypass in Check Point's SmartConsole login process let unauthenticated attackers seize full administrative control of exposed security management servers. Check Point $CHKP found the flaw already being exploited against a small number of customers before it shippe
July 29, 2026 at 5:12 PM