Back to news

Check Point Auth Bypass PoC Goes Public; LG Cracks Down on Smart TV Proxies

A critical Check Point vulnerability now has public exploit code in the wild, while LG moves to purge residential proxy apps from its smart TV platform.

Check Point Auth Bypass PoC Goes Public; LG Cracks Down on Smart TV Proxies

What happened

A proof-of-concept exploit has been publicly released for CVE-2026-16232, a critical authentication bypass flaw in Check Point's SmartConsole login process affecting both Security Management Server and Multi-Domain Security Management Server deployments. The vulnerability carries a CVSS score of 9.3 and has already been observed under active exploitation before the PoC became widely available, raising the urgency for organizations still running unpatched versions. Separately, LG Electronics USA announced plans to suspend any webOS applications found to be enrolling smart televisions as always-on residential proxy nodes — a practice that lets third parties silently route internet traffic through consumers' home networks. The action follows researcher findings that more than 42 percent of apps available on LG's webOS store contained this behavior.

Why it matters for your business

The public release of working exploit code for a near-perfect CVSS score vulnerability dramatically compresses the window organizations have to patch Check Point management infrastructure. Any enterprise using SmartConsole to administer firewall policy is potentially exposed to full management-plane compromise, which could allow attackers to alter security rules, create backdoor access, or extract network topology data. The LG story carries a different but equally serious implication: enterprise devices on the same network segments as employee-owned smart TVs — common in offices, hotels, and shared workspaces — may be silently acting as exit nodes for third-party traffic, creating compliance and attribution risks. Security teams should audit network-connected consumer devices and segment them rigorously from corporate assets.

What to watch next

Check Point customers should treat patching CVE-2026-16232 as an emergency priority given active exploitation and the now-public PoC; incident response teams should audit management server logs for anomalous authentication events predating patch deployment. On the LG front, attention will turn to whether other smart TV operating systems — Roku, Samsung Tizen, Google TV — face similar scrutiny, and whether regulatory bodies in the EU or US use this episode to accelerate rules around embedded proxy software in consumer electronics.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp