AL
Analyst accessPublic view · sign in

Vulnerability threat dossier

CVE-2026-16232

checkpointmulti-domain security management

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

VTP deterministic threat56.7of 100 · CVSS excluded

VTP analyst assessment

No AI candidate assessment for this subject

AI-assisted analytical recommendationDoes not set factual exploitation state
AI classificationNO ALERT
AI priorityNONE
AI confidenceUnknown
Public exploitation · VTP factKEV

Assessment

The latest persisted AI review did not propose this CVE for analyst escalation. Deterministic monitoring remains authoritative for the factual states below.

Why it matters

Unknown from persisted AI analysis.

Evidence

No AI candidate evidence set is persisted for this CVE.

Uncertainties

No first-party sensor telemetry is configured. Local exploitation observation is unknown.

Next watchpoint · deterministic

A validated functional exploit or automated exploitation capability would materially change this assessment.

AI analysis history (0)
    Technical severityCRITICALCVSS 9.3 · technical context
    Public exploitationKEVGlobal public evidence
    Exploit maturityTECHNICAL DETAILSReliability not implied
    EPSS0.7399th percentile · prediction
    Evidence confidence86%Strongest independent active claim
    VelocitySTABLEMaterial events only
    First-party telemetryNo first-party sensor telemetry configured.
    Availability: NO_SENSOR_CONFIGURED · Evidence: UNKNOWN
    01

    VTP deterministic assessment

    Why this matters

    1. 01

      CISA KEV lists this vulnerability as known to be exploited globally.

    2. 02

      EPSS is 0.73; this is predictive context, not exploitation evidence.

    3. 03

      No first-party sensor telemetry is configured; first-party observation is unknown.

    02

    Material change ledger

    What changed

    ZERO DAYZero Day
    RESEARCH PUBLICATIONNew technical research
    ACTIVE EXPLOITATIONActive Exploitation
    ACTIVE EXPLOITATIONActive Exploitation
    RESEARCH PUBLICATIONNew technical research
    KEV ADDEDCISA KEV entry added
    03

    Claim provenance

    Evidence and source independence

    3publications detected
    3underlying evidence chains

    1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

    Source claimACTIVE EXPLOITATIONSOURCE REPORTS ACTIVE EXPLOITATION
    82%claim confidence
    INDEPENDENTreport:7a559b594cd9dbc43715fbbb25c718de5de3c4d531deeb627d7f21f1f5d776fcACTIVE
    Evidence
    Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
    86%claim confidence
    INDEPENDENTreport:7a559b594cd9dbc43715fbbb25c718de5de3c4d531deeb627d7f21f1f5d776fcACTIVE
    Evidence
    Source claimACTIVE EXPLOITATIONSOURCE REPORTS ACTIVE EXPLOITATION
    82%claim confidence
    INDEPENDENTreport:517d32f1bdff82690bf3674fd04fbe53ea45627076902112c64198d7ce20029bACTIVE
    Evidence
    04

    Event history

    Threat timeline

    1. 07:2703 Aug
      EXPLOIT SOURCE UPDATE

      New exploit-source update

      ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-16232.

    2. 18:3228 Jul
      ZERO DAY

      Zero Day

      Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

    3. 18:3228 Jul
      RESEARCH PUBLICATION

      New technical research

      Rapid7 Research published evidence linked to CVE-2026-16232.

    4. 18:3228 Jul
      ACTIVE EXPLOITATION

      Active Exploitation

      Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

    5. 11:5723 Jul
      ACTIVE EXPLOITATION

      Active Exploitation

      Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

    6. 11:5723 Jul
      RESEARCH PUBLICATION

      New technical research

      Rapid7 Research published evidence linked to CVE-2026-16232.

    7. 00:0022 Jul
      KEV ADDED

      CISA KEV entry added

      CISA lists global known exploitation. This is not a VTP sensor observation.

    05

    Original publications

    Source record

    Nuclei Templates v10.4.7 - Release Notes

    New Templates Added: 122 | CVEs Added: 49 | First-time contributions: 23 🔥 Release Highlights 🔥 [CVE-2026-63030] WordPress Core 6.9-7.0.1 - Pre-Auth Batch-Route Confusion ( @slcyber , @mielverkerken , @pdteam , @FLX-0x00 ) [critical] (kev) (vKEV) 🔥 [CVE-2026-60004] Gitea <= 1.27.0 - Pre-Auth Remote Code Execution (@0x_Akoko) [critical] 🔥 [ CVE-2026-58455 ] Dockwatch <= 0.6.567 - OS Command Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-56291 ] Balbooa Forms < 2.4.1 - Unauth Arbitrary File Upload ( @nick Vidovic, @0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-56290 ] Page Builder CK <= 3.5.10 - Unauth File Upload ( @panchiko-p , @0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48908 ] Joomla SP Page Builder <= 6.6.1 - Unauth Arbitrary File Upload RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-46442 ] Flowise < 3.1.2 - node-custom-function Unauth RCE ( @dhiyaneshdk , @princechaddha ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-44825 ] Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials ( @pdteam , @0x_Akoko) [high] (kev) (vKEV) 🔥 [ CVE-2026-16232 ] Check Point Security Management Server - SmartConsole Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-15409 ] SonicWall SMA1000 - Server-Side Request Forgery ( @dhiyaneshdk , @rapid7 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9282 ] W3 Total Cache <= 2.9.4 - Unauth Arbitrary File Read (@0x_Akoko) [high] (kev) (vKEV) 🔥 [ CVE-2026-8732 ] WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauth Administrator Account Creation ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-8713 ] Avada (Fusion) Builder <= 3.15.3 - Unauth Arbitrary File Deletion (@rool-machine) [critical] (kev) (vKEV) 🔥 [ CVE-2026-6875 ] ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE ( @pdteam , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-3296 ] Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-71334 ] Flowise - Path Traversal ( @theamanrawat ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-68493 ] Apache Struts XWork - XML External Entity Injection ( @pussycat0x ) [high] (kev) (vKEV) 🔥 [ CVE-2025-54988 ] Apache Tika - XXE Injection ( @tx1ee ) [critical] 🔥 [ CVE-2025-6389 ] Sneeit WP Social WordPress Plugin - Unauth RCE via call_user_func ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-2505 ] WordPress Age Gate <= 3.5.3 - Unauth Local File Inclusion ( @pussycat0x ) [critical] (kev) (vKEV) 🔥 [CVE-2024-56511] DataEase < 2.10.4 - Authentication Bypass via Whitelist Path Traversal ( @ChrisJr404 ) [critical] 🔥 [ CVE-2023-34992 ] Fortinet FortiSIEM - Unauth Command Injection ( @Thacien ) [critical] 🔥 What's Changed Bug Fixes Stopped credential-stuffing and token-spray templates from sending their first request when no username, password or token is supplied (PR #16589 , Issue #11238 ). Restored missing matcher and extractor values in four templates that silently no-op'd, including CVE-2021-44228 , CVE-2021-45046 and CVE-2026-42281 (PR #16661 ). Replaced an unsupported RE2 lookahead that stopped home-env-permission.yaml from loading at all (PR #16664 ). Added the missing capture group to three regex extractors (PR #16665 ). Corrected the extractor part in portal-api-ssrf from interactsh to interactsh_request (PR #16667 ). Corrected the DSL variable in thinkphp6-arbitrary-write from status_2 to status_code_2 (PR #16668 ). Unhid two extractors marked internal that nothing consumed (PR #16669 ). Marked the setup-stage matchers in CVE-2025-2075 as internal (PR #16671 ). Removed an AWS access key ID from a reference URL in CVE-2024-51482.yaml (PR #16616 ). Fixed an intrusive tag typo in CVE-2023-34124 .yaml (PR #16675 ). Corrected the id and filename for the IBM DB2 Server template (PR #16688 ). Fixed the severity in directory-listing-no-host-header.yaml (PR #16614 ). Corrected the author field for CVE-2024-23108 (PR #16620 ). Moved CVE-2025-29635

    CVE-2008-2052CVE-2019-14793CVE-2021-27877CVE-2021-44228CVE-2021-45046CVE-2021-47795CVE-2023-34124CVE-2023-34992CVE-2023-50839CVE-2024-22476CVE-2024-23108CVE-2024-42323CVE-2024-51482CVE-2024-56511CVE-2025-14047CVE-2025-2075CVE-2025-2505CVE-2025-29635CVE-2025-32969CVE-2025-54988CVE-2025-55746CVE-2025-6389CVE-2025-68493CVE-2025-71334CVE-2026-15094CVE-2026-15409CVE-2026-16232CVE-2026-1830CVE-2026-1980CVE-2026-22683CVE-2026-23550CVE-2026-23696CVE-2026-23829CVE-2026-30623CVE-2026-31831CVE-2026-3296CVE-2026-3335CVE-2026-33497CVE-2026-34036CVE-2026-3891CVE-2026-39468CVE-2026-42281CVE-2026-42796CVE-2026-44825CVE-2026-46442CVE-2026-48908CVE-2026-48909CVE-2026-4987CVE-2026-49952CVE-2026-52773CVE-2026-52824CVE-2026-54836CVE-2026-55450CVE-2026-56290CVE-2026-56291CVE-2026-58455CVE-2026-60004CVE-2026-6043CVE-2026-63030CVE-2026-65694CVE-2026-6875CVE-2026-8385CVE-2026-8713CVE-2026-8732CVE-2026-9198CVE-2026-9282
    Separate evidence group
    Original

    Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)

    Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure. Our analysis finds that the root cause of CVE-2026-16232 is a broken trust boundary in the application authentication path. A vulnerable server accepts an attacker-supplied Secure Internal Communication (SIC) distinguished name (DN) as the identity of a remote application instead of binding that identity to the authenticated remote peer certificate DN returned by getCertificateDnName() . An attacker can read the management server's own SIC DN during the unauthenticated bootstrap communication, replay that DN in a forged application certificate bind, obtain an application token, and then ask the legacy management service to mint a new SmartConsole single sign-on (SSO) ticket. Rapid7 Labs has reproduced CVE-2026-16232 against affected R81.20 and R82.10 versions of the target software. Our proof-of-concept (PoC) exploit script can be used to successfully validate if a target is either vulnerable or patched. The vendor supplied patches have been confirmed to successfully remediate the vulnerability and prevent our PoC script from succeeding. Analysis SmartConsole is the desktop client administrators use to manage Check Point policy and configuration. A SmartConsole login crosses two generations of management plumbing over the network. The first is the legacy FWM/CPMI service, listening on TCP 18190 . It uses SIC, Check Point's certificate-based trust mechanism for communication between management components. Once the SIC bootstrap completes, FWM exchanges length-prefixed “FwSet” objects, a Check Point name/value encoding used by older management services. The second is the newer CPM/DLE service. This exposes SOAP services over HTTPS on TCP 19009 under the URI path /cpmws/ . SmartConsole uses these services for login, queries, and object operations. Authenticated requests carry DLESESSIONID and CLIENTSESSIONID header values to prove a client is authenticated. The exploit for CVE-2026-16232 uses both the FWM/CPMI and CPM/DLE services. It first uses the native FWM/CPMI protocol to claim an application identity and obtain an application token via the root cause of the vulnerability. It then uses the accepted native application session to ask FWM for a SmartConsole SSO ticket, redeems the ticket over CPM's SOAP API, and receives a SmartConsole session. The diagram below shows the flow for exploiting CVE-2026-16232. Figure 1: Flow diagram of exploitation. The application authentication boundary The Java login service contains a bridge for FWM application based logins. The authenticateUser method splits the supplied username into an application name and a SIC DN, then passes both into cpApplicationAuthentication() . // Source: work/t146/mgmt_wrapper.tgz:fw1/cpm-server/dleserver.jar.full!/com/checkpoint/management/dleserver/coresvc/internal/LoginSvcImpl.class private AuthenticationResponse authenticateUser(AuthenticationInfoBase authenticationInfoBase, String string, String string2, CPUUID cPUUID, boolean bl, LockAdminInfoContainer lockAdminInfoContainer, ExternalLoginInfo externalLoginInfo) throws AuthenticationFailureLoginException, LicenseExpiredLoginException { // ... } else if (authenticationInfoBase instanceof FwmAuthenticationInfo) { object2 = authenticationInfoBase.getUse

    CVE-2026-16232
    Separate evidence group
    Original

    CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

    Overview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process classified as improper authentication ( CWE-287 ). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations. Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote exploitation requires network access to the Management Server IP address in environments that do not restrict Trusted Clients. On the same day as the advisory, CVE-2026-16232 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities (KEV), with a remediation due date of July 25, 2026, giving organizations only three days to respond. The advisory addresses three vulnerabilities in total: CVE CVSS Description Affected Products Exploitation Status CVE-2026-16232 Vendor: 9.3 (Critical) CISA: 9.1 (Critical) Authentication bypass via SmartConsole application token Security Management, Multi-Domain Management Exploited in the wild CVE-2026-62144 Vendor: 9.3 (Critical) CISA: 9.1 (Critical) Management authentication bypass and privilege escalation Security Management, Multi-Domain Management No known exploitation CVE-2026-62145 7.5 (High) Local privilege escalation in GaiaOS WebUI Firewall, Multi-Domain Management, Multi-Domain Log Server No known exploitation Compromise of a Security Management Server is particularly consequential because it sits at the top of the trust hierarchy. An attacker with administrative access can modify security policies across managed gateways, alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring. According to Check Point's advisory , the vulnerabilities were discovered during a routine internal review, with subsequent analysis revealing that CVE-2026-16232 had been exploited prior to the availability of a patch. Check Point network security products have been targeted by multiple in-the-wild vulnerabilities over the past two years. In June 2026, CVE-2026-50751 , a critical authentication bypass in Check Point Remote Access VPN, was exploited in the wild and added to the CISA KEV. In May 2024, CVE-2024-24919 , a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was also exploited in the wild. Organizations running affected Check Point management products should apply the available hotfixes on an emergency basis. Technical analysis On July 28, 2026, Rapid7 Labs published a full root cause technical analysis of CVE-2026-16232. Our analysis details the vulnerability and how an unauthenticated attacker can exploit the vulnerability to login to a vulnerable appliance via SmartConsole with full admin privileges. Mitigation guidance Check Point released Jumbo Hotfixes on July 22, 2026, to remediate CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145. Organizations running affected versions of Security Management or Multi-Domain Management should install the latest Jumbo Hotfix on an emergency basis, without waiting for a regular patch cycle to occur. The following versions are affected by CVE-2026-16232: R82.10 : fixed in Jumbo Hotfix Take 36 and later R82 : fixed in Jumbo Hotfix Take 118 and later R81.20 : fixed in Jumbo Hotfix Take 158 and later R81.10 , R81 , R80.30 , R80.20 , R80.10 , R80 , and R77.30 : no fix specified CVE-2026-62144 and CVE-2026-62145 affect the same release families ( R81.10 , R81.20 , R82 , R82.10 ) per the vendor advisory, with older

    CVE-2024-24919CVE-2026-16232CVE-2026-50751CVE-2026-62144CVE-2026-62145
    Separate evidence group
    Original
    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score56.7vtp-threat-v1-public
    Public exploitation30 / 30
    EPSS prediction14.66 / 20
    Exploit availability2.5 / 15
    Source independence7.5 / 15
    Intelligence recency2 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    9.3 · CRITICAL
    Vector
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    CWE
    CWE-287
    CPE records
    122
    Deterministic history records
    6
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    No first-party sensor telemetry configured.