Find notable cyber news and cases, enriched with sources, timelines, and signals.

SmartConsole actively exploited authentication bypass (CVE-2026-16232)

Vulnerability
First reported
Last updated
Happening score
H score 43
3 unique sources, 3 articles

Summary

Hide ▲

Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products. The flaw can let an attacker obtain an application login token, then use full administrator privileges to change security policy and configuration on exposed management environments. Check Point said the issue was observed in the wild against a limited number of customers whose management environments were directly exposed to the Internet without IP restrictions. CISA added the CVE to its KEV catalog and set a July 25 deadline for U.S. federal agencies, while Check Point released patches, mitigations, and IoCs.

Related Happenings

N-able N-central servers hit by network compromise

Incident
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.

CISA BOD 26-04 patch directive for CVE-2026-16232

Public Sector Action
H score37 First: 23.07.2026 11:13 Last: 23.07.2026 11:13 Sources 1

How related: On Wednesday, CISA also added the flaw to its catalog of known exploited vulnerabilities, ordering U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.

About this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...

Check Point Remote Access VPN and Mobile Access authentication bypass (CVE-2026-50751)

Vulnerability
H score47 First: 08.06.2026 16:05 Last: 08.06.2026 16:05 Sources 1

About this happening: Check Point warned that CVE-2026-50751 is a critical authentication bypass in Remote Access VPN and Mobile Access deployments using deprecated IKEv1, letti...

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

Cloud Software Group NetScaler urgent remediation advisory

Advisory/Mitigation
H score44 First: 25.03.2026 17:52 Last: 25.03.2026 17:52 Sources 1

About this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...

Latest development: 31.07.2026 20:35

Unit 42 confirmed three successful compromises of Citrix NetScaler systems via CVE-2026-3055, with the threat actor extracting memory and searching for authentication cookies to hijack sessions, while also conducting manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.

Timeline

  1. 23.07.2026 11:13 2 articles · 13d ago

    CISA adds CVE-2026-16232 to its known exploited vulnerabilities catalog

    Legal Policy Action Update

    CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, under Binding Operational Directive (BOD) 26-04.

    Show sources
  2. 23.07.2026 11:13 3 articles · 13d ago

    Check Point addresses actively exploited SmartConsole zero-day CVE-2026-16232

    Initial Disclosure

    Check Point Software says it has addressed CVE-2026-16232, an actively exploited authentication bypass in SmartConsole that lets unauthenticated attackers obtain an application login token, gain administrator privileges, and modify security policies and security configurations on vulnerable Security Management Server or Multi-Domain Security Management Server deployments exposed to the Internet.

    Show sources