CISA Adds Exploited SharePoint, Check Point Flaws to KEV

CISA Adds SharePoint, Check Point Flaws to KEV Catalog

CRITICAL
July 23, 2026
4m read
VulnerabilityPatch Management

Related Entities

Products & Tech

Microsoft SharePoint Server Check Point SmartConsole

CVE Identifiers

CVE-2026-50522
CRITICAL
CVSS:9.8
CVE-2026-16232
CRITICAL
CVSS:9.3

Full Report

Executive Summary

On July 22, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) took action to address two critical vulnerabilities currently under active attack by adding them to its Known Exploited Vulnerabilities (KEV) Catalog. The two flaws are CVE-2026-50522, a critical deserialization vulnerability in Microsoft SharePoint Server, and CVE-2026-16232, a critical authentication bypass in Check Point SmartConsole. Inclusion in the KEV catalog signifies a high-risk threat to federal networks and, by extension, all organizations using these products. Under Binding Operational Directive (BOD) 22-01, federal agencies are required to remediate these vulnerabilities by July 25, 2026. CISA strongly urges all public and private sector organizations to prioritize these patches to mitigate the risk of compromise.

Vulnerability Details

CVE-2026-50522: Microsoft SharePoint Server Deserialization Vulnerability

  • CVE ID: CVE-2026-50522
  • CVSS Score: 9.8 (Critical)
  • Vulnerability Type: Deserialization of Untrusted Data
  • Description: This vulnerability allows a remote, unauthenticated attacker to execute arbitrary code on a vulnerable SharePoint server. The flaw is reportedly being exploited to steal SharePoint machine keys, which could grant attackers persistent access and the ability to decrypt sensitive data, even after the server is patched.
  • Status: Proof-of-concept (PoC) exploit code is publicly available, and active exploitation has been observed in the wild.

CVE-2026-16232: Check Point SmartConsole Authentication Bypass

  • CVE ID: CVE-2026-16232
  • CVSS Score: 9.3 (Critical)
  • Vulnerability Type: Improper Authentication
  • Description: This vulnerability allows a remote, unauthenticated attacker to bypass authentication and gain full administrative privileges on an internet-exposed Check Point Security Management or Multi-Domain Management server. A compromise gives the attacker full control over the organization's network security policies.
  • Status: Check Point has confirmed limited, targeted exploitation and has released a patch.

Affected Systems

  • CVE-2026-50522: On-premises installations of Microsoft SharePoint Server. SharePoint Online is not affected.
  • CVE-2026-16232: Check Point Security Management and Multi-Domain Management servers (versions R81.10, R81.20, R82, R82.10 and older) that are exposed to the internet.

Exploitation Status

Both vulnerabilities are confirmed to be under active exploitation. The addition to the CISA KEV catalog serves as the highest level of official confirmation of this status. Attackers are actively scanning for and exploiting unpatched systems. The availability of a PoC for the SharePoint flaw has likely accelerated its widespread exploitation.

Impact Assessment

Both vulnerabilities can lead to a full compromise of an organization's network.

  • A successful exploit of the SharePoint flaw gives an attacker a foothold deep within the corporate network, with access to potentially vast amounts of sensitive internal data. The theft of machine keys is particularly damaging, as it undermines the security of the entire SharePoint farm.
  • A successful exploit of the Check Point flaw gives an attacker the "keys to the kingdom" for the network perimeter, allowing them to control all traffic in and out of the organization, disable defenses, and facilitate further attacks.

Detection Methods

  • For CVE-2026-50522:
    • Analyze SharePoint ULS logs and IIS web server logs for suspicious requests, particularly those involving deserialization processes. Look for signs of tools like ysoserial.net.
  • For CVE-2026-16232:
    • Analyze Check Point management server audit logs for successful SmartConsole logins from unexpected or unknown IP addresses.
  • General:
    • Use vulnerability scanners with up-to-date plugins to identify affected systems.

Remediation Steps

  1. Prioritize Patching: All organizations using the affected products must treat these vulnerabilities as a top priority. The deadlines set by CISA for federal agencies are a good benchmark for private sector urgency.
  2. Apply Microsoft Patch: For CVE-2026-50522, apply the security updates for SharePoint Server released by Microsoft.
  3. Apply Check Point Hotfix: For CVE-2026-16232, apply the Jumbo Hotfix Accumulator released by Check Point.
  4. Harden Systems: As a critical compensating control, ensure that management interfaces for both SharePoint and Check Point are not exposed to the public internet. Access should be restricted to trusted internal networks and managed via secure remote access solutions.
  5. Hunt for Compromise: Assume compromise, especially for internet-facing systems. Use the appropriate logs and IOCs to hunt for any signs of exploitation that may have occurred before patching.

Timeline of Events

1
July 22, 2026
CISA adds CVE-2026-50522 and CVE-2026-16232 to the KEV catalog.
2
July 23, 2026
This article was published
3
July 25, 2026
Deadline for U.S. federal agencies to patch the vulnerabilities under BOD 22-01.

MITRE ATT&CK Mitigations

Applying the security updates from Microsoft and Check Point is the most critical step to remediate these vulnerabilities.

Mapped D3FEND Techniques:

Do not expose SharePoint or Check Point management interfaces to the public internet. Restrict access to trusted internal networks.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

Given that both CVE-2026-50522 and CVE-2026-16232 are under active exploitation, the immediate priority is patching. Organizations must treat this as an emergency. For the SharePoint vulnerability, deploy the latest cumulative updates for all on-premises SharePoint farms. For the Check Point flaw, install the specific Jumbo Hotfix Accumulator. The CISA KEV directive provides a clear signal of urgency; all organizations, not just federal agencies, should aim to meet or beat the prescribed deadline. A failure to patch these internet-facing systems is an invitation for compromise.

Both incidents underscore a fundamental security principle: minimize the attack surface of critical infrastructure. Management interfaces for platforms like Check Point SmartConsole and SharePoint Central Administration should never be directly exposed to the public internet. This is a crucial compensating control that would have mitigated the risk of both vulnerabilities. Administrators should immediately audit their network perimeter to identify and remove any public-facing management interfaces. Access should be restricted to internal networks and require users to connect through a multi-factor authenticated VPN or zero-trust network access (ZTNA) solution first.

Timeline of Events

1
July 22, 2026

CISA adds CVE-2026-50522 and CVE-2026-16232 to the KEV catalog.

2
July 25, 2026

Deadline for U.S. federal agencies to patch the vulnerabilities under BOD 22-01.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

CISAKEVSharePointCheck PointCVE-2026-50522CVE-2026-16232zero-day

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.