Jessica Entwistle
July 23 2026
The US Cybersecurity and Infrastructure Security Agency has added two vulnerabilities to its Known Exploited Vulnerabilities catalogue based on evidence of active exploitation in the wild. The vulnerabilities affect Check Point SmartConsole, where an improper authentication flaw tracked as CVE-2026-16232 could allow unauthorised access, and Microsoft SharePoint, where a deserialization vulnerability tracked as CVE-2026-50522 could permit remote code execution. CISA's inclusion of these flaws in the KEV catalogue signals that they are being actively targeted by attackers and that organisations using the affected products should prioritise remediation. Both vulnerabilities have patches available from the respective vendors.
The CISA KEV catalogue remains a valuable reference for prioritising patching activity, even though it is maintained by a US agency. The vulnerabilities listed are typically being exploited in real-world attacks, often by ransomware groups, nation-state actors or opportunistic threat actors scanning for unpatched systems. Check Point SmartConsole is widely used for managing enterprise firewalls and network security infrastructure, and Microsoft SharePoint is a core collaboration platform in many UK organisations. Exploitation of either vulnerability could provide attackers with a foothold in the network, access to sensitive data, or the ability to move laterally across the environment. The fact that these vulnerabilities are now confirmed as exploited means that patching should be treated as a priority rather than a routine update cycle. For UK businesses, this is a reminder that vulnerability management is not just about applying patches when they are released, but about understanding which vulnerabilities are being actively targeted and ensuring that those are addressed first.
Organisations using Check Point SmartConsole or Microsoft SharePoint should verify that patches for CVE-2026-16232 and CVE-2026-50522 have been applied, and that any unpatched instances are identified, isolated or monitored closely until remediation is complete. It is also worth reviewing whether your vulnerability management process includes regular checks against the CISA KEV catalogue as part of patch prioritisation, and whether there is a clear process for escalating and tracking the remediation of known exploited vulnerabilities. For organisations that do not currently monitor the KEV catalogue, it is a straightforward addition to vulnerability management workflows and provides a useful signal for which patches should be prioritised based on real-world threat activity. This is a practical and proportionate step that can help ensure that the most actively targeted vulnerabilities are addressed ahead of lower-risk issues.
Source: CISA