Home / Jul 30, 2026 / Story
0
#6 The Hacker News general July 29, 2026 at 08:58 UTC

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

By [email protected] (The Hacker News)

AI Summary

A public proof-of-concept exploit has been released for CVE-2026-16232 (CVSS 9.3), a critical authentication bypass in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that is already being actively exploited in the wild. The flaw resides in the SmartConsole login process and allows unauthenticated attackers to gain administrative access to firewall management infrastructure. With a PoC now public, organizations running Check Point SMS or MDS should treat this as an emergency patch.

Relevance score: 82.0/100

# More from July 30