Check Point
Security advisories and exploitation reports covering Check Point SmartConsole, firewall appliances, and security gateways — management-plane compromises, policy manipulation, and edge-device vulnerabilities.
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Check Point Quantum Security Gateways Information Disclosure Vulnerability
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

Public PoC Out for Exploited Check Point Admin Bypass
Public PoC is out for CVE-2026-16232, Check Point's CISA KEV-listed admin bypass. Any unpatched SmartConsole server just got cheaper to target — patch or restrict now.

Check Point CVE-2026-16232: Rapid7 Technical Analysis
Rapid7's independent deep-dive into CVE-2026-16232 confirms the auth bypass mechanism and adds MDS deployments to the affected scope. Patch this now.

Check Point SmartConsole Flaw Gives Attackers Admin Access
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.