CVE-2026-16232

CRITICAL KEV

Authentication Bypass in the SmartConsole Login Process Using an Application Token

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-16232 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2026. EIP tracks 2 public exploits from researchers including sfewer-r7, WadesWeaponShed.

AI-analyzed exploit summary This PoC exploits CVE-2026-16232, an authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS). The exploit forges an application bind using the management server's SIC DN to obtain a SmartConsole administrator session token, enabling unauthorized access to sensitive data like administrator records.

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Exploits (2)

nomisec WORKING POC
by sfewer-r7 · poc
https://github.com/sfewer-r7/CVE-2026-16232

This PoC exploits CVE-2026-16232, an authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS). The exploit forges an application bind using the management server's SIC DN to obtain a SmartConsole administrator session token, enabling unauthorized access to sensitive data like administrator records.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Check Point Security Management Server and Multi-Domain Security Management Server (MDS)
No auth needed
Prerequisites: Network access to the target's SIC/CPMI port (default: 18190) and CPM SOAP port (default: 19009) · Target must be running a vulnerable version of Check Point Security Management Server or MDS
mistral-large-3 · analyzed Jul 29, 2026 Full analysis →
nomisec WORKING POC
by WadesWeaponShed · poc
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

This repository contains a functional proof-of-concept tool for auditing and assessing hardening posture of Check Point management servers via the Check Point Management API. It includes server-side and client-side components to scan for misconfigurations, including CVE-2026-16232, and generate hardening reports.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Check Point Management Server (versions affected by CVE-2026-16232)
Auth required
Prerequisites: Valid Check Point Management API credentials (username/password or API key) · Network access to the Check Point Management Server · Node.js environment to run the tool
mistral-large-3 · analyzed Jul 23, 2026 Full analysis →

Scores

CVSS v3 9.1
EPSS 0.1268
EPSS Percentile 95.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-22
VulnCheck KEV 2026-07-19
ENISA EUVD EUVD-2026-47700
CWE
CWE-287
Status published
Products (6)
checkpoint/Multi-Domain Security Management R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
checkpoint/Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below
checkpoint/Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below
checkpoint/Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below
checkpoint/multi-domain_security_management r81.20 (37 CPE variants)
checkpoint/multi-domain_security_management r82 (9 CPE variants)
Published Jul 22, 2026
KEV Added Jul 22, 2026
Tracked Since Jul 22, 2026