Microsoft SharePoint and Check Point SmartConsole Vulnerabilities Under Active Exploitation (heise.de)
0xBASE INTEL BRIEF
- CISA added two critical vulnerabilities to its KEV catalog: SharePoint (CVE-2026-50522, CVSS 9.8) and Check Point SmartConsole (CVE-2026-16232, CVSS 9.1).
- Public proof-of-concept code for the SharePoint flaw was released; watchTowr observed exploitation attempts within hours.
- Patches are available; administrators should apply them urgently and rotate credentials.
"CISA warns of active attacks exploiting a critical SharePoint deserialization vulnerability (CVE-2026-50522, CVSS 9.8) and a Check Point SmartConsole authentication bypass (CVE-2026-16232, CVSS 9.1). Patches are available. Security firm watchTowr discovered public proof-of-concept code for the SharePoint flaw, with exploitation attempts observed within hours. Administrators should patch immediately and rotate credentials on potentially exposed systems."
no comments yet.