Tag: Multi-Domain Security Management Server (MDS)

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
News

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Additional technical information regarding a recently fixed critical security vulnerability affecting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has been actively exploited in the wild has been disclosed by cybersecurity experts. An unauthenticated remote attacker can gain an application login token and use it to authenticate with full administrative privileges thanks to a vulnerability in the SmartConsole login procedure known as CVE-2026-16232 (CVSS score: 9.3). According to Rapid7, an unauthenticated attacker can gain an application login token by exploiting CVE-2026-16232. This token can then be used to enter in through SmartConsole with full administrator capabilities and change the security policy or security settings. An a...