Check Point warns of SmartConsole zero-day exploited in attacks
ID: 43a0f76a-aed3-523c-88c7-e078c70e20af
STIX ID: report--43a0f76a-aed3-523c-88c7-e078c70e20af
Feed Name: Bleeping Computer
Check Point disclosed an actively exploited zero-day (CVE-2026-16232) in SmartConsole allowing unauthenticated attackers to obtain application login tokens and authenticate with administrator privileges, enabling modification of security configurations and policies; CISA added the flaw to its known exploited vulnerabilities catalog and ordered federal patching. The advisory includes mitigation guidance (patching, restricting Trusted Clients and management access), a SmartConsole audit log query with IP indicators to check for compromise, and notes limited customer impact so far.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
