Check Point has patched a critical flaw in SmartConsole, the web-based console administrators use to manage its firewalls, after confirming it was already being used against a small number of customers. Tracked as CVE-2026-16232 and rated 9.3 out of 10, the bug lets an attacker with no valid account grab a login token that SmartConsole treats as a fully authenticated administrator session — no password, no second factor, nothing.
The flaw sits in the Security Management Server and Multi-Domain Security Management components, the pieces that hold the master configuration for an organisation's firewalls, versions R77.30 through R82.10. It only works if the management server's GUI client access is reachable from the internet without being locked down to specific admin IP addresses — the exposure Check Point's own hardening guide has long recommended closing off, but which some deployments never got around to. Once an attacker has that token, they can view and rewrite the security policy that decides what traffic a firewall allows or blocks.
Check Point says it found the issue during a routine internal review, then discovered it was already being exploited against a handful of customers and has notified them directly, sharing six known attacker IP addresses. Patches (a Jumbo hotfix) shipped 22 July. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered US federal agencies to patch by 25 July — a signal of how seriously it's treating active exploitation, not a sign the risk is limited to government networks.
What this means for your business
- This applies only if you or your IT provider runs a Check Point firewall managed through SmartConsole — if you don't know your firewall vendor, that's the first thing to ask.
- Ask whoever manages it two direct questions this week: is the July 22 hotfix installed, and is the management server's GUI/admin access restricted to specific trusted IP addresses rather than open to the whole internet?
- Restricting admin access by IP closes the door even before patching finishes — it's the single fastest mitigation if the hotfix can't go in immediately.
- Have logs checked for unexpected admin sessions or policy changes since mid-July, especially if the console has ever been reachable without IP restrictions.
A firewall's management console is the one system where a five-minute conversation with whoever runs it is worth more than any amount of worrying alone.