cybersecuritydive.com • 3h
Critical Authentication Bypass in Check Point SmartConsole CVE-2026-16232
CVE-2026-16232 is a critical authentication bypass vulnerability in Check Point SmartConsole affecting Security Management Servers and MDS (R81.20, R82.10). Attackers exploit a broken trust boundary in the Secure Internal Communication (SIC) bootstrap process by replaying the server's own SIC Distinguished Name (DN) to obtain an application login token. This token is then used to request a SmartConsole Single Sign-On (SSO) ticket via the CPM SOAP API, granting full system_admin privileges. Exploitation has been observed since April 2026, enabling attackers to rewrite security policies, create unauthorized VPN tunnels, and disable logging. Immediate patching via vendor-supplied Jumbo Hotfixes is required.