A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available. Tracked as CVE-2026-16232, the flaw affects Security Management Server and Multi-Domain Security Management Server (MDS) and can give an unauthenticated attacker full administrator access through the SmartConsole management interface. On July 22, 2026, Check Point published a security advisory detailing the issue, while Rapid7 Labs confirmed exploitation in the wild and released a public proof-of-concept to help defenders validate exposure. CVE-2026-16232 sits in the SmartConsole login path. An attacker with network reach to the Management Server can obtain an application login token, use it to authenticate...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!