CVE-2026-16232Checkpoint · Multi-domain_security_management
Vulnerability data via NVD (ingested)
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-16232product:"Checkpoint Multi-domain Security Management"http.html:"Multi-domain Security Management"More intel sources (5)
vuln:CVE-2026-16232vulnerabilities.cve_id: CVE-2026-16232CVE-2026-16232CVE-2026-16232"CVE-2026-16232" exploit -site:nvd.nist.gov