
Researchers release proof-of-concept for exploited Check Point admin-takeover flaw as patch adoption lags
CVE-2026-16232, a CVSS 9.3 authentication bypass in Check Point's SmartConsole login process, lets an unauthenticated attacker seize full administrator control of Security Management Servers. Rapid7 published a public proof-of-concept this week, raising the stakes for organizations that haven't yet applied the July 22 hotfix.










