CVE-2026-16232CISA KEVEPSS p99.6%
CVE-2026-16232Check Point SmartConsole Improper Authentication Vulnerability
Check Point / SmartConsole
Description
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 77.97% probability of exploitation · percentile 99.6% · 2026-10-03T12:00:21Z |
| Last modified | 2026-08-10 |
CISA KEV entry
Added to KEV: 2026-07-22