CVE-2026-16232CISA KEVEPSS p99.6%

CVE-2026-16232Check Point SmartConsole Improper Authentication Vulnerability

Check Point / SmartConsole

Description

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS77.97% probability of exploitation · percentile 99.6% · 2026-10-03T12:00:21Z
Last modified2026-08-10

CISA KEV entry

Added to KEV: 2026-07-22

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.