Key Findings Check Point SmartConsole authentication bypass CVE-2026-16232 is actively exploited in the wild with a critical CVSS score of 9.3 Attackers can bypass login using an application token to gain full administrative access without credentials Only a small number of customers with specific configurations are currently targeted, primarily those exposing Management directly to the internet Two additional authentication and privilege escalation flaws were also disclosed: