← Knowledge Center
Zero-Day CVE-2026-16232, CVE-2026-50522

CISA Flags Actively Exploited Check Point SmartConsole Auth Bypass in KEV Catalog

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The most identity-relevant is CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole—the management interface for Check Point security infrastructure. An authentication weakness in such an administrative console can allow attackers to bypass access controls and potentially gain privileged access to security management functions. The second flaw, CVE-2026-50522, is a deserialization of untrusted data vulnerability in Microsoft SharePoint.

These additions fall under Binding Operational Directive (BOD) 26-04, which requires Federal Civilian Executive Branch agencies to rapidly remediate high-risk KEV-listed vulnerabilities on publicly exposed assets, prioritizing those that grant total control post-exploitation. The directive also sets expectations for checking whether systems were compromised before patching.

What to take away: An authentication bypass in a security management console like SmartConsole is a high-value target, since compromise there can cascade into broader control of the environment. Organizations should patch affected Check Point and SharePoint systems immediately and hunt for signs of prior compromise, not just apply the fix.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.