Check Point SmartConsole authentication bypass (CVE-2026-16232): exploited in the wild - act now
An unauthenticated attacker can obtain a valid SmartConsole login token and sign in to Check Point Security Management with full administrative privileges. It's being exploited as a zero-day and CISA added it to the KEV catalog on 22 July 2026. Here's the briefing, the exposure test, and the action list.
