#6
The Hacker News
general
July 29, 2026 at 08:58 UTC
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
By [email protected] (The Hacker News)
AI Summary
A public proof-of-concept exploit has been released for CVE-2026-16232 (CVSS 9.3), a critical authentication bypass in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that is already being actively exploited in the wild. The flaw resides in the SmartConsole login process and allows unauthenticated attackers to gain administrative access to firewall management infrastructure. With a PoC now public, organizations running Check Point SMS or MDS should treat this as an emergency patch.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →