Global Check Point SmartConsole zero-day exploitation
Check Point says CVE-2026-16232 is a critical authentication-bypass flaw in SmartConsole that has been exploited in the wild, allowing unauthenticated attackers to obtain a login token and gain full admin access to Security Management and Multi-Domain Management systems. They urge patching and hardening, noting only a small number of customers are affected and that exposure of management servers to the internet without IP restrictions is the key risk, with CISA adding the vulnerability to KEV and mandating patching by July 25.