View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Check Point patches SmartConsole zero-day CVE-2026-16232 exploited

🚨 ACTIVE EXPLOITATION

  • Check Point patches SmartConsole zero-day CVE-2026-16232 exploited in attacks — BleepingComputer
    Check Point patched an authentication bypass zero-day in SmartConsole actively exploited in the wild.
    • Applies to Check Point Security Management and Multi-Domain Management products
    • CVE-2026-16232 allows unauthenticated attackers to obtain admin login tokens
    • Attackers can remotely access Management Server if exposed to the Internet without IP restrictions
    • Exploitation enables modification of security policies and configurations via SmartConsole GUI
    • CISA added CVE-2026-16232 to Known Exploited Vulnerabilities catalog, requiring urgent patching

💥 BREACHES & INCIDENTS

🕵️ RESEARCH & DEEP DIVES

  • Chaos ransomware group uses msaRAT malware to route C2 traffic via Chrome and Edge browsers — BleepingComputer
    Chaos ransomware group deploys msaRAT malware that routes C2 traffic through Chrome and Edge browsers.

    • Targets Windows environments via phishing and remote management software installation
    • msaRAT is a Rust-based backdoor using Chrome DevTools Protocol to control headless Chrome or Edge
    • Routes command-and-control traffic through browser using Cloudflare Workers and Twilio TURN servers
    • Communication encrypted with WebRTC DTLS and ChaCha20-Poly1305 + ECDH keys
    • Avoids direct network connections to C2 infrastructure, evading detection and tracing
  • Researchers find three actors probing CVE exploit paths weeks before public disclosure — honeylabs.net
    Three distinct IP actors probed exact CVE exploit paths weeks before public advisories appeared.

    • Applies to internet-exposed services including cPanel WHM and LMDeploy vision module
    • Probes targeted specific vulnerable endpoints matching CVE exploit signatures before public disclosure
    • Detection based on analysis of 30 million honeypot probes with four strict filters to remove false positives
    • Earliest confirmed probe was 18 days before CVE-2026-41940 advisory for cPanel authentication bypass
    • Other early probes include 56 days before CVE-2026-33626 (server-side request forgery) and 57 days before CVE-2026-8181

🔓 CVEs & KEV

  • 21 CVEs reported without scores this cycle.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check