CISA Confirms Active Exploitation of Critical Check Point and Microsoft SharePoint Flaws
Two enterprise-facing vulnerabilities added to CISA’s Known Exploited Vulnerabilities Catalog require urgent patching, exposure review and forensic triage. On 22 July 2026, the U.S. Cybersecurity and Infrastructure Security Agency added two serious vulnerabilities to its Known Exploited Vulnerabilities Catalog after confirming evidence of active exploitation: CVE-2026-16232 — Check Point SmartConsole authentication bypass. CVE-2026-50522 — Microsoft SharePoint deserialization vulnerability. Both vulnerabilities affect high-value enterprise infrastructure. One can provide administrative control over security-management systems, while the other can enable unauthenticated remote code execution on vulnerable SharePoint servers. CISA set 25 July 2026 as the remediation deadline for affected U.S. federal civilian agencies, demonstrating the urgency attached to both flaws. 1. Check Point SmartConsole Authentication Bypass CVE: CVE-2026-16232 Type: Improper authentication ...