SmartConsole actively exploited authentication bypass (CVE-2026-16232)
Vulnerability
Summary
Hide ▲
Show ▼
Check Point has patched CVE-2026-16232, an actively exploited authentication bypass in SmartConsole that can let unauthenticated attackers seize administrator privileges on management servers. Successful exploitation can change security configuration and security policy on exposed Security Management Server and Multi-Domain Security Management Server deployments. The flaw is most dangerous where the management interface is reachable from the Internet and Trusted Clients are not tightly restricted. CISA added the issue to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch by July 25.
Related Happenings
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector Action
H score37
First: 23.07.2026 11:13
Last: 23.07.2026 11:13
Sources 1
How related:
On Wednesday, CISA also added the flaw to its catalog of known exploited vulnerabilities, ordering U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.
About this happening:
CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector ActionHow related: On Wednesday, CISA also added the flaw to its catalog of known exploited vulnerabilities, ordering U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.
About this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA updates KEV entry for CVE-2026-1731
Public Sector Action
H score36
First: 20.02.2026 17:45
Last: 20.02.2026 17:45
Sources 1
About this happening:
CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
CISA updates KEV entry for CVE-2026-1731
Public Sector ActionAbout this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
CISA KEV patch order for Dell RecoverPoint
Public Sector Action
H score36
First: 19.02.2026 17:30
Last: 19.02.2026 17:30
Sources 1
About this happening:
CISA added CVE-2026-22769 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by February 21. The directive unde...
CISA KEV patch order for Dell RecoverPoint
Public Sector ActionAbout this happening: CISA added CVE-2026-22769 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by February 21. The directive unde...
Timeline
-
23.07.2026 11:13 1 articles · 0h ago
CISA adds CVE-2026-16232 to its known exploited vulnerabilities catalog
Legal Policy Action UpdateCISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, under Binding Operational Directive (BOD) 26-04.
Show sources
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13
-
23.07.2026 11:13 2 articles · 0h ago
Check Point addresses actively exploited SmartConsole zero-day CVE-2026-16232
Initial DisclosureCheck Point Software says it has addressed CVE-2026-16232, an actively exploited authentication bypass in SmartConsole that lets unauthenticated attackers obtain an application login token, gain administrator privileges, and modify security policies and security configurations on vulnerable Security Management Server or Multi-Domain Security Management Server deployments exposed to the Internet.
Show sources
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13