highZero-Day

CISA KEV Catalog Update: Check Point SmartConsole and Microsoft SharePoint Actively Exploited Vulnerabilities

First seen Jul 23, 2026 · Updated Jul 23, 2026

CISAKEVCheck PointSmartConsoleSharePointdeserializationauthentication-bypassactive-exploitationfederal-agenciesagent-relevant

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper authentication flaw in Check Point SmartConsole (CVE-2026-16232) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-50522). Both are confirmed to be exploited in the wild, prompting mandatory remediation timelines for FCEB agencies under BOD 26-04 and a strong recommendation for all organizations to patch immediately.

Technical Analysis

CVE-2026-16232 affects Check Point SmartConsole, allowing attackers to bypass authentication controls, potentially granting unauthorized administrative access to security management infrastructure. CVE-2026-50522 is a deserialization of untrusted data vulnerability in Microsoft SharePoint, a class of bug that typically enables remote code execution when an attacker supplies crafted serialized objects processed by vulnerable endpoints. Both vulnerabilities grant significant post-exploitation control, meeting CISA's KEV criteria for high-risk assets, and are likely being weaponized by threat actors for initial access, lateral movement, or persistence. Organizations running self-hosted SharePoint instances that back internal RAG pipelines, document ingestion for LLM tools, or knowledge bases used by AI agents are at risk of data exfiltration or code execution that could poison agent context or leak credentials/API keys stored in connected systems, making this agent-relevant. Immediate patching and compromise assessment (per BOD 26-04 guidance) are critical given active exploitation.

Affected Systems

Check Point SmartConsole (versions affected by CVE-2026-16232, per vendor advisory); Microsoft SharePoint Server (on-premises deployments affected by CVE-2026-50522, per vendor advisory)

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published in this CISA alert; organizations should consult vendor advisories and CISA KEV Catalog entries for updated indicators.

Remediation Steps

  1. 1

    Apply Vendor Patches

    Immediately apply Check Point's and Microsoft's official security updates addressing CVE-2026-16232 and CVE-2026-50522 respectively.

  2. 2

    Compromise Assessment

    Per BOD 26-04, determine whether systems were compromised prior to patching by reviewing logs, authentication events, and deserialization-related anomalies.

  3. 3

    Restrict Public Exposure

    Limit internet-facing access to SmartConsole and SharePoint management interfaces; enforce network segmentation and VPN/MFA-gated access.

  4. 4

    Audit Agent-Connected Systems

    For organizations using SharePoint as a data source for RAG pipelines or AI agent knowledge bases, audit connected service accounts, API keys, and ingestion pipelines for signs of compromise or data poisoning.

  5. 5

    Monitor KEV Catalog

    Continuously track the CISA KEV Catalog for newly added vulnerabilities and align patch management prioritization accordingly.

CVE / Advisory IDs

CVE-2026-16232CVE-2026-50522

Industries Most Exposed

GovernmentFederal Civilian Executive BranchTechnologyFinanceHealthcareCritical InfrastructureAll sectors using Check Point or SharePoint

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.