Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ‘Farage’s got to come clean or clear off’: what voters on Clacton beach think about their MP – and the country | Nigel Farage

    July 29, 2026

    Ariana Grande is suing the hackers who’ve been leaking her songs and videos for years

    July 29, 2026

    Liquid AI Releases LFM2.5-Encoder-230M and LFM2.5-Encoder-350M: Bidirectional Encoders That Stay Fast at 8K Context on CPU

    July 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ‘Farage’s got to come clean or clear off’: what voters on Clacton beach think about their MP – and the country | Nigel Farage
    • Ariana Grande is suing the hackers who’ve been leaking her songs and videos for years
    • Liquid AI Releases LFM2.5-Encoder-230M and LFM2.5-Encoder-350M: Bidirectional Encoders That Stay Fast at 8K Context on CPU
    • Spur Raises $200 Million for IP Intelligence Platform
    • Binance offers gold and silver options after commodity futures pull in billions in daily volume
    • Fatal WWII bomb blast in Indonesia was a result of illegal fishing activity, police say
    • Northern Lights fleet ready for phase one as fourth LCO2 carrier arrives from China
    • France and Spain brace for fresh heatwave as warnings issued over risk of new wildfires – Europe live | Europe
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, July 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 29, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 29, 2026Vulnerability / Enterprise Security

    Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.

    The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

    “By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration,” Rapid7 said.

    Successful exploitation requires an attacker to have network access to the Management Server and a configuration that does not restrict Trusted Clients. Check Point has disclosed that it’s aware of a handful of customers being targeted by this flaw as a zero-day.

    Rapid7 analysis of the vulnerability has uncovered that the root cause is a “broken trust boundary” in the application authentication path that permits the threat actor to log in to a vulnerable appliance via SmartConsole with full admin privileges.

    Cybersecurity

    Specifically, a vulnerable server has been found to accept an attacker-supplied Secure Internal Communication (SIC) distinguished name (DN) as the identity of a remote application as opposed to binding that identity to the authenticated remote peer certificate DN returned by a function named “getCertificateDnName().”

    As a result, an attacker can read the management server’s own SIC DN during the unauthenticated bootstrap communication and authenticate as a remote application by replaying that management server’s DN, obtaining an application login token, and then minting a new SmartConsole single sign-on (SSO) ticket via the forged application session.

    The patch introduced by Check Point ensures that remote clients use the authenticated remote peer certificate DN, causing any mismatch between the supplied DN and that authenticated identity to be rejected. It also adds a new empty identity check that prevents a remote application login when there is no authenticated SIC identity.

    “To make the supplied server DN survive the patched checks, the attacker would need an authenticated client certificate whose subject DN already matches that server DN, which removes the unauthenticated bypass,” Rapid7’s Stephen Fewer said.

    Rapid7 has released a proof-of-concept (PoC) Python script that can be used to successfully validate whether a target is either vulnerable or patched against the flaw.

    Customers are advised to apply the Jumbo Hotfixes released by Check Point on July 22, 2026, to remediate the flaw as soon as possible.

    Authentication Bypass check Exploited PoC Point public Released SmartConsole
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Spur Raises $200 Million for IP Intelligence Platform

    Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

    The CSO’s blind spot: Why platform engineering 2.0 is now a security imperative

    OT Security Startup Frenos Raises $1.52 Million

    Why Resetting Passwords No Longer Stops Attackers

    Former Citigroup CISO Blauner on What Makes A Great Leader

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ‘Farage’s got to come clean or clear off’: what voters on Clacton beach think about their MP – and the country | Nigel Farage

    July 29, 2026

    Ariana Grande is suing the hackers who’ve been leaking her songs and videos for years

    July 29, 2026

    Liquid AI Releases LFM2.5-Encoder-230M and LFM2.5-Encoder-350M: Bidirectional Encoders That Stay Fast at 8K Context on CPU

    July 29, 2026

    Spur Raises $200 Million for IP Intelligence Platform

    July 29, 2026
    Latest Posts

    DNV awards world’s first certification for wave energy technology

    July 21, 2026

    Tropical Storm Bertha threatens US Gulf coast

    July 21, 2026

    Road deaths fall by 21% globally but stronger action is needed to save lives

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ‘Farage’s got to come clean or clear off’: what voters on Clacton beach think about their MP – and the country | Nigel Farage

    July 29, 2026

    Ariana Grande is suing the hackers who’ve been leaking her songs and videos for years

    July 29, 2026

    Liquid AI Releases LFM2.5-Encoder-230M and LFM2.5-Encoder-350M: Bidirectional Encoders That Stay Fast at 8K Context on CPU

    July 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.