- Sources: CISA KEV catalog, Check Point sk185169, CVE-2026-50522 (NVD)
- Summary: CISA KEV catalog version 2026.07.22 (count 1653) added two flaws on 2026-07-22, both federal-due 2026-07-25. CVE-2026-16232 is an improper-authentication flaw in Check Point SmartConsole (CVSS 9.3, sk185169): an unauthenticated remote attacker can obtain an application login token and authenticate with full administrative privileges, letting them alter firewall, VPN, and logging policy. It requires reaching the Management Server IP without Trusted-Clients restriction, and is fixed in the R82.10 Jumbo Hotfix from Take 36 and the R82 Jumbo from Take 118. CVE-2026-50522 is another Microsoft SharePoint deserialization-of-untrusted-data RCE (unauthenticated network code execution), the fourth July SharePoint KEV entry after CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644.
- Why it matters: Both target internet-facing management and collaboration infrastructure under active exploitation, and the two-day federal remediation window signals urgency.
- Follow-up: Watch for ransomware follow-on and internet-exposure scans of unpatched SmartConsole and SharePoint hosts.
send feedback on this story