ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-16232CVE-2026-50522CVE-2026-58644

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-16232
Authentication Bypass in Check Point SmartConsole Grants Full Admin Access

Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released.

Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing.

9.372% KEV
  • Check Point SmartConsole
  • Check Point Quantum Security Management
  • Check Point Multi-Domain Security Management
largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no…
CVE-2026-50522
+1 in the same advisory: …58644
Unauthenticated Deserialization RCE in Microsoft SharePoint Server

CVE-2026-50522 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows an unauthenticated attacker to send maliciously crafted serialized data over the network and execute code on the server, reflected in its 9.8 critical CVSS score with no privileges or user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability, giving attackers a foothold for follow-on actions such as data theft, lateral movement, or ransomware. Any organization running on-premises SharePoint Server is in scope, particularly deployments reachable from untrusted networks; the required action notes stakeholders must evaluate each asset's internet exposure under CISA BOD 26-04. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-22 and security news headlines describe it as a critical RCE exploited in the wild, with some reports referencing exploitation after a public proof-of-concept release and an authentication bypass. The structured record lists no public PoC as confirmed, but an EPSS of 84.6% (100th percentile) underscores a very high near-term exploitation likelihood.

Do: Apply Microsoft's security updates for SharePoint Server immediately per the vendor advisory, as required under CISA's KEV listing and BOD 26-04, and prioritize any SharePoint deployments that are internet-facing (federal/critical-infrastructure operators must follow BOD 26-04 timelines or discontinue unmitigated use). Until patched, restrict public access to SharePoint endpoints (VPN, firewall rules, or reverse proxy) and review IIS/application logs and running processes for signs of unauthenticated deserialization abuse. Because some reports reference an authentication bypass being chained, also verify authentication paths and monitor for follow-on attacker activity after patching.

9.885% KEV
  • Microsoft SharePoint Server (on-premises)
massorder of 100,000+ on-prem SharePoint Server deployments worldwide, with tens of thousands plausibly internet-exposed
Full article653 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SharePoint and Check Point flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the KeV catalog:

  • CVE-2026-16232 (CVSS score of 9.3) Check Point SmartConsole Improper Authentication Vulnerability
  • CVE-2026-50522 (CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

The first flaw added to the KeV catalog is a critical authentication bypass flaw, tracked as CVE-2026-16232, affecting Security Management and Multi-Domain Management (MDSM).

The vulnerability, which is under active exploitation, allows unauthenticated remote attackers to obtain a SmartConsole login token and gain full administrative access.

“An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers.” reads the advisory. “Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).”

Successful exploitation requires the Management Server to be accessible from the internet and Trusted Clients (GUI client) access restrictions to be disabled.

Check Point said it is aware of a limited number of customers targeted through CVE-2026-16232 and has already notified the affected organizations. The following attacker IP addresses have been identified as indicators of compromise (IoCs):

  • 151.241.99[.]207
  • 151.241.99[.]233
  • 158.62.198[.]182
  • 192.142.10[.]99
  • 139.28.37[.]250
  • 194.213.18[.]137

The flaw impacts the following products and versions:

  • Products: Security Management Server, Multi-Domain Security Management Server (MDS)
  • Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10

The second issue added to the catalog is a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522, that is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.

Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.

CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction, and stemming from the deserialization of untrusted data. CVE-2026-50522 was demonstrated live at Pwn2Own Berlin, meaning a working exploit was handed to Microsoft. Despite that, the advisory lists exploit maturity as unknown.

Organizations should apply the available security updates immediately.

watchTowr observed active exploitation of CVE-2026-50522 targeting on-premises Microsoft SharePoint servers shortly after public exploit code was released. Attackers are using the flaw to steal SharePoint machine keys in a single request, enabling persistent access even after patching. Security experts warn that organizations should not only apply Microsoft’s updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise.

“On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability. Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.” watchTowr wrote on LinkedIn. “Attackers are pulling SharePoint machine keys via a single request. Patching is not enough, defenders should rotate credentials on any assets that may have been exposed.”

Cybersecurity firm Defused Cyber also spotted threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload through a SharePoint sign-in endpoint. The observed attacks require no authentication, consistent with the vulnerability’s unauthenticated remote code execution profile.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix these flaws by July 25, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/195889/security/u-s-cisa-adds-microsoft-sharepoint-and-check-point-smartconsole-flaws-to-its-known-exploited-vulnerabilities-catalog.html