🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVE
CVE-2026-16232
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
quantum security managementmulti-domain security management
Updated Sep 18, 2026View on NVD →
This CVE is in S4E's catalog, but no public scanner is mapped to it yet.
CVE history: quantum security management
Predict next CVE date with AIMonitor this CVE on your assets
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →