---
title: "Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public"
url: https://daily.dev/posts/check-point-smartconsole-authentication-bypass-is-under-active-attack-and-a-poc-is-now-public-gygbdb6p9
source_url: https://latesthackingnews.com/2026/08/02/smartconsole-authentication-bypass
type: article
source: "Latest Hacking News"
published: 2026-08-02T11:06:58.881Z
updated: 2026-08-02T11:07:20.390Z
tags: ["security"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public

**[Latest Hacking News](https://daily.dev/sources/lhn)** · 5 min read · 0 upvotes · 0 comments

## Summary

Check Point has confirmed active exploitation of CVE-2026-16232, a critical authentication bypass (CVSS 9.3) in SmartConsole's Security Management and Multi-Domain Management servers. The flaw allows an unauthenticated attacker to gain full administrator access by exploiting how the login process handles SIC identities — accepting an attacker-supplied distinguished name without validating it against the peer certificate. Rapid7 published a technical breakdown and a public Python PoC on GitHub that can also verify patch status. CISA added the CVE to its Known Exploited Vulnerabilities catalogue with a three-day remediation deadline for federal agencies. Emergency Jumbo Hotfixes are available for R81.20, R82, and R82.10. Affected organizations should apply the hotfix immediately, restrict Trusted Clients to known IP addresses, and avoid exposing management servers directly to the internet.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://latesthackingnews.com/2026/08/02/smartconsole-authentication-bypass>

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/check-point-smartconsole-authentication-bypass-is-under-active-attack-and-a-poc-is-now-public-gygbdb6p9)
