A critical vulnerability in Check Point Software’s SmartConsole login process is being exploited, with a small number of customers already impacted, according to a security advisory released Wednesday from the company.
The authentication bypass flaw, tracked as CVE-2026-16232, allows an attacker to gain full administrative privileges after they access an application login token. An attacker can then make changes to security policy and configurations. The vulnerability has a severity score of 9.1 out of 10.
Check Point on Wednesday released a jumbo hotfix to address several security issues in its firewall and management products, according to the advisory.
A vulnerability of this type is particularly concerning, giving an attacker the ability to make a number of changes, according to a blog post released Thursday by Rapid7. A remote hacker can “alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring,” Rapid7 said.
“To put it simply, this vulnerability targets the system that tells the firewalls what to trust,” said Douglas McKee, director of vulnerability intelligence at Rapid7.
The vulnerability was discovered by Check Point during a routine internal review. Remote exploitation is possible only when there is internet access to the Management Server IP address in environments that do not restrict Trusted Clients, according to Rapid7.
The Cybersecurity and Infrastructure Security Agency on Wednesday added the SmartConsole vulnerability to its Known Exploited Vulnerabilities catalog. The agency set a deadline of Saturday for Federal Civilian Executive Branch agencies to mitigate their environments.
The jumbo hotfix also addresses CVE-2026-62144, a critical authentication bypass vulnerability in Check Point Security Management and CVE-2026-62145, a high severity flaw in Check Point Gaia Portal.