EXPOSURES › CVE-2026-16232
CVE-2026-16232
HIGH ⌖ ON CISA KEV · EXPLOITEDCheck Point SmartConsole had unpatched RCE allowing remote admin access
Check Point's SmartConsole had an unpatched improper authentication vulnerability that allowed remote attackers to obtain admin access using stolen login tokens, leading to potential data breaches and unauthorized system control.
Shame score — Critical unpatched vulnerability enabling remote code execution and administrative access.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.