DIRAS TAKE
Urgent: this vulnerability is high risk and is on CISA’s Known Exploited Vulnerabilities list with a short remediation window; immediately restrict or isolate affected management interfaces and apply vendor instructions at once.
What is CVE-2026-16232?
Remote, unauthenticated attackers can acquire a session token that grants full administrative access to Check Point SmartConsole, letting them change policies and management settings. CVE-2026-16232 impacts a wide range of Quantum Security Management and Multi-Domain Security Management releases, including R82.10 (Jumbo Hotfix Take 36 or below), R82 (JHT 118 or below), R81.20 (JHT 158 or below) and many builds from R81.10 through R77.30. Successful exploitation requires network reachability to the Management Server IP and a management setup that does not limit Trusted Clients. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Check Point SmartConsole are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Quantum Security Management | R82.10 with Jumbo Hotfix Take 36 or below | |
| Quantum Security Management | R82 with Jumbo Hotfix Take 118 or below | |
| Quantum Security Management | R81.20 with Jumbo Hotfix Take 158 or below | |
| Quantum Security Management | R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 | |
| Multi-Domain Security Management | R82.10 with Jumbo Hotfix Take 36 or below | |
| Multi-Domain Security Management | R82 with Jumbo Hotfix Take 118 or below | |
| Multi-Domain Security Management | R81.20 with Jumbo Hotfix Take 158 or below | |
| Multi-Domain Security Management | R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 |
Is CVE-2026-16232 being exploited?
CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog on 2026-07-22, with a remediation due date of 2026-07-25; public exploit code is also available.
How to fix CVE-2026-16232
- Limit access to SmartConsole and Management Server IPs to trusted administrative networks and VPNs only.
- Implement any Check Point mitigation guidance immediately and follow their recommended hardening steps.
- Monitor authentication and administrative logs for unexpected token issuance or configuration changes and investigate anomalies.
- If you cannot sufficiently restrict remote access, isolate or discontinue exposed management instances until mitigations or fixes are available.
Frequently asked questions
Is CVE-2026-16232 being actively exploited?
Yes. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog on 2026-07-22 and public exploit code is available.
Which SmartConsole versions are affected by CVE-2026-16232?
The affected list includes multiple Quantum Security Management and Multi-Domain Security Management builds such as R82.10 (JHT 36 or below), R82 (JHT 118 or below), R81.20 (JHT 158 or below) and various R81.10 through R77.30 releases.
Is there a patch for CVE-2026-16232?
No fixed versions are listed in the provided facts; follow Check Point mitigation guidance, restrict access to affected SmartConsole instances, and apply vendor instructions when a patch becomes available.
Does CVE-2026-16232 require authentication?
No. An unauthenticated remote attacker can obtain a session token and gain administrative access to Check Point SmartConsole when the Management Server is reachable and Trusted Clients are not restricted.
References
- nvd.nist.gov/vuln/detail/CVE-2026-16232
- cve.org/CVERecord?id=CVE-2026-16232
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232
- support.checkpoint.com/results/sk/sk185169
- All Check Point CVEs on CVE Radar
- CVEs published in September 2026