Robotics & Physical AIJul 23, 2026

Patch now: Check Point SmartConsole and Microsoft SharePoint flaws join CISA's exploited list

On July 22, 2026, CISA added two actively exploited flaws to its Known Exploited Vulnerabilities catalog: an improper-authentication bug in Check Point SmartConsole (CVE-2026-16232, CVSS 9.3) that hands attackers an admin login token, and an unauthenticated deserialization remote-code-execution flaw in Microsoft SharePoint (CVE-2026-50522, CVSS 9.8). The SharePoint flaw is being used to steal machine keys, which keep working even after patching — affected servers need the patch AND key rotation.

What it means On-prem SharePoint operators must patch and rotate machine keys — patching alone leaves stolen keys valid.

Where it came from CISA

Back to the Stream