Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has issued security upgrades to fix a number of vulnerabilities affecting Security Management and Multi-Domain Management (MDSM) products, including a serious weakness that has been actively exploited in the wild.
An unauthenticated remote attacker can gain an application login token and use it to authenticate with full administrative privileges thanks to a security hole known as CVE-2026-16232 (CVSS score: 9.3) that affects the Check Point SmartConsole login procedure.
According to a description of the vulnerability on CVE.org, successful exploitation enables the attacker to change security parameters and policies. A configuration that does not limit Trusted Clients and internet access to the Management Server IP address are prerequisites for remote exploitation.
Che...

