U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
2026-07-23T20:51:50Z•9fff28b95d8d69e726bb6c8feeb736ae5c75f77cf7ce628810c8e622d7b5b842
Adobe Acrobat extensionCISA KEVChaos ransomwareCheck Point SmartConsoleMicrosoft SharePointRCESNMPUbuntu snapZimbraactive exploitationauthentication bypassbrowser-based C2command injectionmsaRATprivilege escalationpublic PoCsnap sandboxthreat intelvulnerability disclosurezero-day testing
What happened
Multiple high-severity vulnerabilities and active exploitation events were reported across widely used products. CISA added a number of flaws (including SharePoint and Check Point SmartConsole issues) to its Known Exploited Vulnerabilities (KEV) catalog. A public PoC triggered active exploitation of critical Microsoft SharePoint RCE CVE-2026-50522 (CVSS 9.8). Check Point patched an actively exploited SmartConsole authentication bypass (CVE-2026-16232, CVSS 9.3). Qualys disclosed a local privilege escalation in Ubuntu snap-confine (CVE-2026-8933). Adobe fixed an extension vulnerability (CVE-202
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 9fff28b95d8d69e726bb6c8feeb736ae5c75f77cf7ce628810c8e622d7b5b842
- Enrichment time
- 2026-07-23T20:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.