SevenTnewS

CISA

CISA adds two actively exploited flaws to its must-patch catalog

CISA added CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog, requiring rapid remediation for federal agencies. The advisory definitions behind these listings clarify how industrial control and medical device vulnerabilities are disclosed and mitigated.

Emmanuel Fabrice Omgbwa Yasse AI-assisted

2026-08-02 · 2 min read

CISA adds two actively exploited flaws to its must-patch catalog

CISA added two more entries to its Known Exploited Vulnerabilities catalog this week, and neither is the kind you patch next Tuesday. The first, CVE-2026-16232, is an authentication bypass in Check Point SmartConsole. The second, CVE-2026-50522, is a deserialization bug in Microsoft SharePoint. Both are under active attack, according to the agency a related alert on the SharePoint flaw.

For federal agencies, the listing triggers Binding Operational Directive 26-04, which sets a patching deadline based on risk. But outside .gov, the real value is in how CISA explains what these entries mean. The agency runs two advisory tracks that handle most of its vulnerability bulletins, and the difference matters for anyone running industrial or medical equipment the coming wave of AI-discovered patches.

Two advisories, one logic

An ICS Advisory (ICSA) covers software flaws in industrial control systems, operational technology, and IoT devices. An ICS Medical Advisory (ICSMA) does the same for medical devices. Both list affected models, give vulnerability details, and point to vendor fixes. Together they are the authoritative source for OT and healthcare defenders the broader shift toward AI-driven defensive responses.

Neither Check Point nor SharePoint fall into those categories: they are enterprise IT products, not OT or medical. But the KEV catalog covers everything the federal enterprise runs. That wider scope is what makes the catalog useful: it catches flaws the advisory system was not designed to flag the KEV catalog's steady expansion.

A catalog that keeps filling

CISA adds vulnerabilities to the KEV list when they meet three conditions: a valid CVE ID, confirmed real-world exploitation, and clear remediation steps. The agency pushes private-sector organizations to follow the same risk-based logic. BOD 26-04 also requires agencies to check whether any of their systems were compromised before the patch went in the evolving playbook of digital extortion.

The two new entries push the active KEV count past several hundred. Each one is an attack vector someone in the wild is already using. For anyone running these products, the agency's guidance is direct: if you have them on your network, assume they have been compromised until you prove otherwise.

Get the tech essentials in 3 minutes every morning

One email, every weekday, with what actually matters in AI and tech.