Check Point has confirmed active exploitation of CVE-2026-16232, a critical authentication bypass (CVSS 9.3) in SmartConsole's Security Management and Multi-Domain Management servers. The flaw allows an unauthenticated attacker to gain full administrator access by exploiting how the login process handles SIC identities — accepting an attacker-supplied distinguished name without validating it against the peer certificate. Rapid7 published a technical breakdown and a public Python PoC on GitHub that can also verify patch status. CISA added the CVE to its Known Exploited Vulnerabilities catalogue with a three-day remediation deadline for federal agencies. Emergency Jumbo Hotfixes are available for R81.20, R82, and R82.10. Affected organizations should apply the hotfix immediately, restrict Trusted Clients to known IP addresses, and avoid exposing management servers directly to the internet.