
CISA adds actively exploited Check Point SmartConsole flaw to KEV catalog
CISA added actively exploited Check Point SmartConsole CVE-2026-16232 to KEV after a July 22 vendor hotfix advisory.
CISA has added a newly disclosed Check Point SmartConsole vulnerability to its Known Exploited Vulnerabilities catalog after evidence of active exploitation, putting federal agencies and exposed enterprise management servers on a short remediation clock. The flaw, tracked as CVE-2026-16232, affects Check Point Quantum Security Management and Multi-Domain Security Management deployments and was disclosed in a July 22 security advisory from Check Point.
Check Point describes the bug as an authentication bypass in the SmartConsole login process using an application token. In vulnerable configurations, an unauthenticated remote attacker could obtain an application login token and authenticate with full administrative privileges. That level of access matters because SmartConsole is used to manage security policies and configurations, so a compromise can become a direct route to changing the controls an organization relies on to filter traffic and enforce access rules.
What administrators should know
The vendor says exploitation has affected a handful of customers and is tied to a specific risky setup: management exposed directly to the internet without IP restrictions. Check Point says Smart-1 Cloud customers are already protected, and it has notified affected customers. The advisory lists CVE-2026-16232 as a CVSS 9.3 issue and says supported releases including R81.10, R81.20, R82, and R82.10 are affected, with older versions also impacted.
CISA's separate July 22 alert added both CVE-2026-16232 and a Microsoft SharePoint deserialization issue, CVE-2026-50522, to the KEV catalog. Inclusion in KEV is not a theoretical severity label; it means CISA has evidence that attackers are exploiting the vulnerability in real environments. For U.S. federal civilian agencies, KEV entries trigger required remediation under Binding Operational Directive 22-01, and private-sector defenders often use the catalog as a high-priority patch queue.
Recommended action
- Install the latest Check Point jumbo hotfix released on July 22, 2026.
- Restrict Trusted Clients, including GUI clients, to trusted IP addresses and subnets.
- Protect management access with firewall rules and avoid exposing management interfaces directly to the internet.
- Review Check Point's listed indicators of compromise and investigate any matching activity.
The practical takeaway is narrow but urgent: organizations running internet-reachable Check Point management should treat the update as an active-attack response, not routine maintenance.
Sources
Cover photo by Brett Sayles on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment