SmartConsole actively exploited authentication bypass (CVE-2026-16232)
Vulnerability
Summary
Hide ▲
Show ▼
Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products. The flaw can let an attacker obtain an application login token, then use full administrator privileges to change security policy and configuration on exposed management environments. Check Point said the issue was observed in the wild against a limited number of customers whose management environments were directly exposed to the Internet without IP restrictions. CISA added the CVE to its KEV catalog and set a July 25 deadline for U.S. federal agencies, while Check Point released patches, mitigations, and IoCs.
Related Happenings
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentAbout this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector Action
H score37
First: 23.07.2026 11:13
Last: 23.07.2026 11:13
Sources 1
How related:
On Wednesday, CISA also added the flaw to its catalog of known exploited vulnerabilities, ordering U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.
About this happening:
CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector ActionHow related: On Wednesday, CISA also added the flaw to its catalog of known exploited vulnerabilities, ordering U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.
About this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
Check Point Remote Access VPN and Mobile Access authentication bypass (CVE-2026-50751)
Vulnerability
H score47
First: 08.06.2026 16:05
Last: 08.06.2026 16:05
Sources 1
About this happening:
Check Point warned that CVE-2026-50751 is a critical authentication bypass in Remote Access VPN and Mobile Access deployments using deprecated IKEv1, letti...
Check Point Remote Access VPN and Mobile Access authentication bypass (CVE-2026-50751)
VulnerabilityAbout this happening: Check Point warned that CVE-2026-50751 is a critical authentication bypass in Remote Access VPN and Mobile Access deployments using deprecated IKEv1, letti...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/Mitigation
H score44
First: 25.03.2026 17:52
Last: 25.03.2026 17:52
Sources 1
About this happening:
Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/MitigationAbout this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Latest development: 31.07.2026 20:35
Unit 42 confirmed three successful compromises of Citrix NetScaler systems via CVE-2026-3055, with the threat actor extracting memory and searching for authentication cookies to hijack sessions, while also conducting manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.
Timeline
-
23.07.2026 11:13 2 articles · 13d ago
CISA adds CVE-2026-16232 to its known exploited vulnerabilities catalog
Legal Policy Action UpdateCISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, under Binding Operational Directive (BOD) 26-04.
Show sources
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass — thehackernews.com — 29.07.2026 11:58
-
23.07.2026 11:13 3 articles · 13d ago
Check Point addresses actively exploited SmartConsole zero-day CVE-2026-16232
Initial DisclosureCheck Point Software says it has addressed CVE-2026-16232, an actively exploited authentication bypass in SmartConsole that lets unauthenticated attackers obtain an application login token, gain administrator privileges, and modify security policies and security configurations on vulnerable Security Management Server or Multi-Domain Security Management Server deployments exposed to the Internet.
Show sources
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13
- New Check Point Zero-Day Vulnerability Exploited in the Wild — www.securityweek.com — 23.07.2026 12:06