PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Aug 2, 2026

Check Point Security Management Server - SmartConsole Authentication Bypass

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Quantum Security Managementby checkpoint
R82.10 with Jumbo Hotfix Take 36 or below
Multi-Domain Security Managementby checkpoint
R82.10 with Jumbo Hotfix Take 36 or below
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Check Point Security Management Server - SmartConsole Authentication Bypass CVE-2026-16232 Scanner | S4E