The Check Point zero-day wasn't after your firewall: it was after its console
CVE-2026-16232: an authentication bypass in SmartConsole allowed logging into the server that governs all your Check Point gateways as an administrator, with no credentials. It was exploited before the patch existed and CISA gave three days to remediate. Why the management plane is a bigger prize than the firewall itself, and the checklist that applies even without Check Point.