CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The most identity-relevant is CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole—the management interface for Check Point security infrastructure. An authentication weakness in such an administrative console can allow attackers to bypass access controls and potentially gain privileged access to security management functions. The second flaw, CVE-2026-50522, is a deserialization of untrusted data vulnerability in Microsoft SharePoint.
These additions fall under Binding Operational Directive (BOD) 26-04, which requires Federal Civilian Executive Branch agencies to rapidly remediate high-risk KEV-listed vulnerabilities on publicly exposed assets, prioritizing those that grant total control post-exploitation. The directive also sets expectations for checking whether systems were compromised before patching.
What to take away: An authentication bypass in a security management console like SmartConsole is a high-value target, since compromise there can cascade into broader control of the environment. Organizations should patch affected Check Point and SharePoint systems immediately and hunt for signs of prior compromise, not just apply the fix.