Firewalls exist so the bad guys have to work for it. Check Point's SmartConsole just handed out a skeleton key instead, and CISA is not thrilled about it.
An Unauthenticated Path to Admin
Tracked as CVE-2026-16232, the flaw lives in SmartConsole's authentication handling and scores a nasty 9.3 out of 10 on the CVSS scale. An unauthenticated remote attacker can obtain an application login token that grants full administrative access — no password, no MFA prompt, no are-you-sure dialog, just a straight shot to the controls.
It hits SmartConsole on versions R81.10, R81.20, R82, and R82.10, with older releases potentially at risk too. CISA has already added it to its Known Exploited Vulnerabilities catalog and confirms it's being actively used in the wild. So far the damage is described as limited to customers who left management interfaces exposed directly to the internet, but "limited" is doing a lot of load-bearing work in that sentence.
Why a Firewall Company's Bug Is Everyone's Problem
SmartConsole isn't some peripheral admin panel — it's the control tower for an organization's entire firewall and security policy stack. An attacker who lands a valid login token can rewrite security rules, open holes in the perimeter, and generally redecorate the network however they like, all while the firewall itself keeps humming along like nothing's wrong.
The fix already exists: Check Point shipped a Jumbo Hotfix on July 22 that closes the hole. The bigger lesson, as always, is that "management interface reachable from the open internet" should be a fireable offense on any security team, not a Tuesday. Restrict access to trusted IPs, patch now, check your logs.
A 9.3 on the box that controls your firewall is the security equivalent of finding out your front door lock only works on days ending in "y." Patch it before someone else notices.
If this has you rethinking your own infrastructure, we build and harden sites for a living — say hello.
Source: Cybersecurity News