CISA Adds Two New Actively Exploited Vulnerabilities to KEV Catalog
CISA has updated its Known Exploited Vulnerabilities (KEV) catalog to include two new flaws affecting Check Point SmartConsole and Microsoft SharePoint, which are currently being used by attackers in the wild.

English Brief
CISA has updated its Known Exploited Vulnerabilities (KEV) catalog to include two new flaws affecting Check Point SmartConsole and Microsoft SharePoint, which are currently being used by attackers in the wild.
الموجز العربي
وكالة الأمن السيبراني الأمريكية تضيف ثغرتين جديدتين مستغلتين فعلياً إلى قائمة الثغرات المعروفة
قامت وكالة الأمن السيبراني الأمريكية بتحديث قائمة الثغرات المعروفة (KEV) لتشمل ثغرتين جديدتين تؤثران على برامج Check Point SmartConsole وMicrosoft SharePoint، حيث يتم استغلالهما حالياً من قبل المهاجمين.
- 1Identify instances of Check Point SmartConsole and Microsoft SharePoint in the environment. # 2. Check vendor portals for security patches corresponding to CVE-2026-16232 and CVE-2026-50522. # 3. Apply updates immediately in accordance with vendor guidance. # 4. Audit logs for indicators of unauthorized access or suspicious deserialization activity prior to patching.
English Advisory
// Intelligence Summary
CISA has officially added CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its Known Exploited Vulnerabilities (KEV) catalog. These additions signify confirmed active exploitation in the wild, necessitating immediate attention to maintain organizational security posture.
التقرير العربي
// ملخص استخباراتي
قامت وكالة الأمن السيبراني وأمن البنية التحتية الأمريكية (CISA) بإضافة الثغرتين CVE-2026-16232 (الخاصة بـ Check Point SmartConsole) وCVE-2026-50522 (الخاصة بـ Microsoft SharePoint) إلى قائمة الثغرات المستغلة المعروفة (KEV). يشير هذا الإدراج إلى تأكيد استغلال هذه الثغرات في هجمات فعلية، مما يتطلب اهتماماً فورياً للحفاظ على مستوى الأمان المؤسسي.
// Technical Context
CVE-2026-16232 relates to improper authentication mechanisms within Check Point SmartConsole, potentially allowing unauthorized access. CVE-2026-50522 involves a deserialization of untrusted data vulnerability in Microsoft SharePoint, a class of vulnerability often leveraged for Remote Code Execution (RCE).
// السياق الفني
تتعلق الثغرة CVE-2026-16232 بآليات مصادقة غير صحيحة داخل Check Point SmartConsole، مما قد يسمح بالوصول غير المصرح به. بينما تتضمن الثغرة CVE-2026-50522 خللاً في إلغاء تسلسل البيانات غير الموثوق بها (Deserialization) في Microsoft SharePoint، وهو نوع من الثغرات التي غالباً ما تستخدم لتنفيذ تعليمات برمجية عن بُعد (RCE).
// Exposure Notes
These vulnerabilities pose a risk to enterprise environments utilizing the aforementioned software. Organizations running Check Point SmartConsole or Microsoft SharePoint are at risk if patches are not applied, particularly if these assets are internet-facing.
// ملاحظات التعرض
تشكل هذه الثغرات خطراً على بيئات المؤسسات التي تستخدم البرامج المذكورة أعلاه. المنظمات التي تستخدم هذه الأنظمة معرضة للخطر في حال عدم تطبيق التحديثات الأمنية، خاصة إذا كانت هذه الأصول متصلة بالإنترنت بشكل مباشر.
// Defensive Priority
Per Binding Operational Directive (BOD) 26-04, federal agencies must prioritize patching these vulnerabilities. Private sector organizations are strongly encouraged to adopt a risk-based approach and expedite remediation for these identified KEV catalog entries.
// أولوية الدفاع
وفقاً للتوجيه التشغيلي الملزم (BOD) 26-04، يجب على الوكالات الفيدرالية إعطاء الأولوية لتصحيح هذه الثغرات. كما يُنصح القطاع الخاص بشدة باعتماد نهج قائم على المخاطر وتسريع عمليات المعالجة لهذه الثغرات المدرجة في قائمة KEV.
Mitigation Checklist
- 1Identify instances of Check Point SmartConsole and Microsoft SharePoint in the environment. # 2. Check vendor portals for security patches corresponding to CVE-2026-16232 and CVE-2026-50522. # 3. Apply updates immediately in accordance with vendor guidance. # 4. Audit logs for indicators of unauthorized access or suspicious deserialization activity prior to patching.
قائمة إجراءات التخفيف
- 1تحديد نسخ Check Point SmartConsole وMicrosoft SharePoint الموجودة في بيئة العمل. # 2. مراجعة مواقع الشركات المصنعة للحصول على التحديثات الأمنية الخاصة بالثغرات CVE-2026-16232 وCVE-2026-50522. # 3. تطبيق التحديثات فوراً وفقاً لتوجيهات الشركة المصنعة. # 4. فحص سجلات النظام بحثاً عن أي مؤشرات لوصول غير مصرح به أو نشاط مشبوه قبل إجراء التحديث.
- Source: CISA Alerts
# 1. Identify instances of Check Point SmartConsole and Microsoft SharePoint in the environment. # 2. Check vendor portals for security patches corresponding to CVE-2026-16232 and CVE-2026-50522. # 3. Apply updates immediately in accordance with vendor guidance. # 4. Audit logs for indicators of unauthorized access or suspicious deserialization activity prior to patching.