Close Menu
    What's Hot

    Should AI companies be able to outsource safety?

    Opinion | Is More Data About Your Body Actually Good for You?

    The Cuban Throwing Parties to Fight for Political Change

    Facebook X (Twitter) Instagram
    Trending
    • Should AI companies be able to outsource safety?
    • Opinion | Is More Data About Your Body Actually Good for You?
    • The Cuban Throwing Parties to Fight for Political Change
    • St James’s Place inflows drop as UK pensions tax change looms
    • Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
    • Opinion | I Hope This Column Ages Poorly
    • Opinion | Elon Musk Is a Menace to Society
    • Opinion | Trump’s Chaos Is a Job Killer
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

    adminBy adminJuly 29, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 29, 2026Vulnerability / Enterprise Security

    Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

    Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.

    The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

    “By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration,” Rapid7 said.

    Successful exploitation requires an attacker to have network access to the Management Server and a configuration that does not restrict Trusted Clients. Check Point has disclosed that it’s aware of a handful of customers being targeted by this flaw as a zero-day.

    Rapid7 analysis of the vulnerability has uncovered that the root cause is a “broken trust boundary” in the application authentication path that permits the threat actor to log in to a vulnerable appliance via SmartConsole with full admin privileges.

    Cybersecurity

    Specifically, a vulnerable server has been found to accept an attacker-supplied Secure Internal Communication (SIC) distinguished name (DN) as the identity of a remote application as opposed to binding that identity to the authenticated remote peer certificate DN returned by a function named “getCertificateDnName().”

    As a result, an attacker can read the management server’s own SIC DN during the unauthenticated bootstrap communication and authenticate as a remote application by replaying that management server’s DN, obtaining an application login token, and then minting a new SmartConsole single sign-on (SSO) ticket via the forged application session.

    The patch introduced by Check Point ensures that remote clients use the authenticated remote peer certificate DN, causing any mismatch between the supplied DN and that authenticated identity to be rejected. It also adds a new empty identity check that prevents a remote application login when there is no authenticated SIC identity.

    “To make the supplied server DN survive the patched checks, the attacker would need an authenticated client certificate whose subject DN already matches that server DN, which removes the unauthenticated bypass,” Rapid7’s Stephen Fewer said.

    Rapid7 has released a proof-of-concept (PoC) Python script that can be used to successfully validate whether a target is either vulnerable or patched against the flaw.

    Customers are advised to apply the Jumbo Hotfixes released by Check Point on July 22, 2026, to remediate the flaw as soon as possible.

    Authentication Bypass check Exploited PoC Point Public Released SmartConsole
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleOpinion | I Hope This Column Ages Poorly
    Next Article St James’s Place inflows drop as UK pensions tax change looms
    admin
    • Website

    Related Posts

    OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

    July 29, 2026

    Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

    July 29, 2026

    Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

    July 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Should AI companies be able to outsource safety?

    Opinion | Is More Data About Your Body Actually Good for You?

    The Cuban Throwing Parties to Fight for Political Change

    St James’s Place inflows drop as UK pensions tax change looms

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by