Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)


On July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure.

Read more…
Source:  


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Update your iPhone, iPad, or Mac: Flaw could run attackers’ code

    September 29, 2026

    Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27. The fix is in iOS and iPadOS 26.7.1, ...

  • Pentagon breach exposed sensitive data on nearly 3 million people

    September 29, 2026

    A breach of the Pentagon’s sprawling personnel database exposed sensitive information belonging to a massive swath of military personnel, including Social Security numbers and details about the jobs they held, according to a U.S. defense official. The breach affected 2.76 million living people and another 294,000 who are deceased, the official said. The scope and sensitivity ...

  • Fake iPhone Duo preorder scam triggers DarkSword attack

    September 29, 2026

    Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what MalwareBytes researchers found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud. But one fake preorder page was different. Read more… Source:  MalwareBytes Labs Sign up for the Cyber Security Review ...

  • Recently disclosed Citrix vulnerabilities exploited in the wild

    September 28, 2026

    Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered critical flaws in Citrix’s NetScaler application delivery controller and gateway products to that grim list. On Sunday, the company published a bulletin warning of eight CVEs, the worst of which – CVE-2026-88771 and CVE-2026-88772 – ...

  • CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

    September 23, 2026

    On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending ...

  • Meta Muse already has a majorly worrying zero-day security issue

    September 22, 2026

    Meta’s new Artificial Intelligence (AI) assistant Muse reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email. However, it’s not as straightforward as your usual zero-day – to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before ...