CISA Adds SharePoint and Check Point SmartConsole Flaws to Known Exploited Vulnerabilities Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the active exploitation of vulnerabilities in Microsoft SharePoint and Check Point Software Technologies SmartConsole.
On July 22, 2026, CISA added CVE-2026-50522 and CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies have been instructed to apply mitigations by July 25, 2026, while all organizations are urged to take immediate action due to the widespread exploitation risk.
CVE-2026-50522 resides in Microsoft SharePoint and enables remote attackers to execute arbitrary code by deserializing untrusted data. The flaw received a CVSS v3.1 base score of 9.8 and is rated Critical. A security update addressing the issue was included in Microsoft’s July 14, 2026 Patch Tuesday release. Coordinated disclosure occurred, and no exploitation was known at the time the advisory was published.
CVE-2026-16232 affects the SmartConsole management tool from Check Point Software Technologies. The vulnerability stems from improper authentication, allowing attackers to obtain administrative rights and modify security configurations and policies. Check Point has published a list of IP addresses observed in attacks and is advising customers to investigate potential compromises.
Security researchers note that both vulnerabilities are being actively leveraged in the wild, increasing the urgency for patching across enterprise environments.
Related articles
Agent, Scan or Beyond: Modern Methods for Comprehensive Infrastructure Vulnerability Scanning
The eighth installment in the Vulnerability Management for Beginners series explains why traditional scanning approaches no longer cover today's dynamic environments. It details three classic methods—Host Discovery, Pentest, and Audit—alongside agent-based scanning, cloud snapshot techniques, passive traffic analysis, container and SCA tools, and integrations with existing IT systems. The guide stresses that agents from Tenable and Qualys complement but do not replace network scanning, while Orca Security and Wiz pioneered disk snapshot analysis for short-lived cloud instances. It also covers container image scanning with Trivy and Grype before deployment, passive monitoring for OT environments, and the importance of combining multiple data sources to eliminate blind spots. Practical recommendations include scanning frequency by asset type and six post-scan steps for effective remediation.
CVE-2026-20349: Cisco ASA and FTD Firewalls Face Remote DoS in SSL VPN, Already Exploited
Cisco has disclosed a high-severity denial-of-service vulnerability affecting its Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense products. The flaw, tracked as CVE-2026-20349, resides in the SSL VPN component and allows unauthenticated remote attackers to trigger device reboots by sending specially crafted HTTP requests. The issue also impacts FTD deployments using Zero Trust Network Access. With a CVSS v3.1 base score of 8.6, the vulnerability has already been observed in active exploitation campaigns since August 2026. Cisco released hotfixes for both affected platforms and strongly urges immediate updates, while confirming that Secure Firewall Management Center remains unaffected.
Adobe Releases Third Emergency Patch for Campaign Classic in Two Weeks, Fixing Critical RCE Vulnerabilities
Adobe has issued another urgent security update for Adobe Campaign Classic after discovering multiple critical vulnerabilities that affect the previous patches released on July 29 and August 3. The new advisory, published on August 11, 2026, addresses three CVEs rated Critical, including two remote code execution flaws with CVSSv3.1 base scores of 10.0. These authorization bypass issues allow unauthenticated attackers to execute arbitrary code remotely. The affected versions include 7.4.3 build 9398 and build 9399, which were themselves emergency fixes issued only days earlier. Adobe urges all customers to apply the latest update immediately due to the high risk of exploitation. This marks the third high-severity patch for the product within a two-week period.
SonicWall Global Management System Hit by Critical RCE and Path Traversal Vulnerabilities
SonicWall has disclosed six vulnerabilities in its SonicWall Global Management System (GMS) management product, with the highest-severity issues rated Critical. The most severe flaw, CVE-2026-66147, resides in the Dispatcher Service and allows unauthenticated remote code execution through crafted requests that inject commands. A second critical issue, CVE-2026-66145, stems from improper handling of zip archive extraction and enables path traversal attacks that can read sensitive data or write arbitrary files without authentication. Both vulnerabilities received CVSSv3 base scores above 9.0. The flaws affect both the virtual appliance and Windows versions of GMS. SonicWall released an advisory on August 11 urging immediate application of the available updates.