Check Point Warns of SmartConsole Zero-Day Exploited in Active Attacks — Patch Now

Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day vulnerability in its SmartConsole graphical user interface (GUI) admin panel, warning customers that attackers have been exploiting the flaw in the wild.

Tracked as CVE-2026-16232 with a CVSS score of 9.3 (critical), the flaw is an authentication bypass affecting the SmartConsole login process. An unauthenticated remote attacker can obtain an application login token and use it to authenticate with full administrative privileges.

“Successful exploitation allows the attacker to modify security policies and security configurations,” according to the vulnerability description. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict trusted clients.

Who is affected?

Check Point has released security updates for its Security Management and Multi-Domain Management (MDSM) products. Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a small number of customers being targeted by this flaw and has already notified them directly. The company has not disclosed the nature of the attacks or when they were first discovered.

Critically, the vulnerability only affects deployments where the Management Server is exposed directly to the internet without IP restrictions. Organizations following security best practices—keeping management interfaces behind firewalls and VPNs—are not affected.

Indicators of compromise

Check Point has shared the following IP addresses associated with the exploitation activity:

  • 151.241.99.207
  • 151.241.99.233
  • 158.62.198.182
  • 192.142.10.99
  • 139.28.37.250
  • 194.213.18.137

Additional patches

Check Point also released patches for two other vulnerabilities alongside the zero-day fix, including another authentication bypass flaw with a CVSS score of 9.3 (CVE-2026-62144). Organizations running Check Point security management products are strongly advised to apply the latest updates immediately and ensure management interfaces are not exposed to the public internet.

spot_imgspot_img

Subscribe

Related articles

spot_imgspot_img