CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog after reports of active exploitation against Check Point SmartConsole. The flaw, mapped to CWE-287 Improper Authentication, affects Check Point Quantum Security Management and Multi-Domain Security Management and allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges.
Check Point said the issue has affected a very small number of customers, while CISA set a 2026-07-25 remediation deadline under BOD 26-04 and directed organizations to apply vendor mitigations and conduct forensics triage. Successful exploitation can let attackers modify security policies and configurations, and remote attacks are possible when the Management Server is reachable and Trusted Clients restrictions are not in place. CISA’s broader KEV update also added CVE-2026-50522 affecting Microsoft SharePoint, bringing the catalog total to 1,653 entries.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On July 22, 2026, CISA updated the SSVC assessment for CVE-2026-16232 from no exploitation to active exploitation. The update also added a KEV catalog reference and CVSS v3.1 vector details.
CISA added CVE-2026-16232 affecting Check Point SmartConsole to its Known Exploited Vulnerabilities catalog as a vulnerability exploited in the wild. The entry set a remediation due date of 2026-07-25 and noted that ransomware use was unknown.
Check Point stated that CVE-2026-16232, an authentication bypass in the SmartConsole login process, is being exploited and has affected a very small number of customers. The flaw allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges.
MITRE published CWE-287, defining the weakness category for improper authentication. This provides the weakness classification referenced for the later Check Point flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.