Security Management and SmartConsole
CVE-2026-16232: Authentication Bypass in the SmartConsole Login Process Using an Application Token
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Quantum Security Management R82.10 with Jumbo Hotfix Take 36 or below | See the advisory |
| Quantum Security Management R82 with Jumbo Hotfix Take 118 or below | See the advisory |
| Quantum Security Management R81.20 with Jumbo Hotfix Take 158 or below | See the advisory |
| Quantum Security Management R81.10, R81, R80 | See the advisory |
| Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below | See the advisory |
| Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below | See the advisory |
| Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below | See the advisory |
| Multi-Domain Security Management R81.10, R81, R80 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Exploitation
CISA lists this CVE as exploited in the wild since 22 Jul 2026.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.