CVE-2026-16232
CWE-287
103.6
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Source: NVD
Signals
- CVSS
- 9.8
- Critical · v3.1
- EPSS
- 77.97%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Jul 2026
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-287
- Published
- 22 Jul 2026
- Last modified 10 Aug 2026
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2026-16232Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time