CISA KEV 22 Jul 2026: 2 exploited flaws in Check Point and Microsoft
2 vulnerabilities
AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
On 22 July 2026, CISA added 2 actively exploited vulnerabilities affecting Check Point, Microsoft to its Known Exploited Vulnerabilities catalog. If you run any of these products, patch or mitigate now — exploitation is already happening.
CVE-2026-16232Federal deadline
In this section
Check Point SmartConsole Improper Authentication Vulnerability
Check Point / SmartConsole / CWE-287
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft / SharePoint / CWE-502
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.