SevenTnewS

Cybersecurity

Two new CISA alerts, one hard question: did they get in before you patched?

CISA adds CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog. Under BOD 26-04, agencies must now check for pre-patch compromises and prioritize by risk, making breach detection just as critical as patching speed.

Emmanuel Fabrice Omgbwa Yasse AI-assisted

2026-07-25 · 3 min read

Two new CISA alerts, one hard question: did they get in before you patched?
Sources : CISA Alerts

The U.S. Cybersecurity and Infrastructure Security Agency on Wednesday expanded its Known Exploited Vulnerabilities catalog with two entries: an improper authentication flaw in Check Point SmartConsole (CVE-2026-16232) and a deserialization vulnerability in Microsoft SharePoint (CVE-2026-50522). Both are under active exploitation, though neither CISA nor either vendor has published technical details or attribution for the attacks yet.

The Check Point bug targets SmartConsole, the unified management interface for firewalls and security gateways. Improper authentication means an unauthenticated attacker could land inside the administrative plane of a Check Point environment, potentially reconfiguring rules, exfiltrating logs, or pivoting deeper into the network. SmartConsole sits at a privileged intersection, so a successful exploit here is not just a network intrusion, it is administrative access handed to someone who should not have it. This pattern of targeting privileged admin interfaces aligns with tactics seen in sophisticated campaigns, such as the use of Umbrij malware to hijack sessions via OAuth token theft, as documented by researchers tracking the ToddyCat APT group.

Schéma : BOD 26-04 Remediation Workflow for KEV Vulnerabilities
Based on the article, BOD 26-04 mandates a pre-patch compromise assessment before applying fixes, distinguishing vulnerability management from breach management.

The SharePoint vulnerability is a deserialization-of-untrusted-data issue, a class of flaw that has historically plagued the platform. This is not the first SharePoint bug CISA has flagged this year: in June 2026, the agency added CVE-2026-45659, a remote code execution vulnerability in the same product, to its KEV catalog following confirmed exploitation linked to the Storm-2603 threat group and an unidentified second actor, as reported at the time. The new CVE-2026-50522 suggests attackers maintaining interest in SharePoint as a vector, or that the previous round of patches did not close every door.

Both additions fall under the framework of Binding Operational Directive 26-04, which CISA published earlier this year to replace the simpler time-based patching mandates of earlier BODs. BOD 26-04 requires Federal Civilian Executive Branch agencies to treat KEV-listed vulnerabilities on publicly exposed assets as an emergency class, but with a twist: the directive orders agencies to prioritize remediation based on risk, specifically, vulnerabilities that grant total control of the asset post-exploitation, while deferring lower-risk CVEs. More importantly, it adds a forensic check before patching: agencies must determine whether threat actors already compromised the system before applying the fix.

This is a meaningful shift. Previous directives focused on patching speed (how fast, measured in days). BOD 26-04 adds a detection obligation (were you already compromised?). The cybersecurity landscape has already seen attackers exploiting these gaps, including a fully AI-run ransomware attack discovered by Sysdig researchers that exploited an unpatched Langflow flaw, illustrating the speed at which automated threats can move. For organizations that have been treating KEV alerts as a patch trigger rather than an incident-response trigger, the new expectation changes the operational workflow.

Neither CVE-2026-16232 nor CVE-2026-50522 have public exploit code available as of writing, but active exploitation means proof-of-concept or in-the-wild tooling exists privately. Federal agencies have a standard remediation window, typically within 7 days for critical KEV entries, to patch and to conduct the mandated pre-patch compromise check. For non-FCEB organizations, CISA makes the same recommendation without the legal obligation: treat KEV entries as urgent, run a compromise assessment, patch, and assume the gap between exploitation and detection matters.

The broader takeaway is not just that two more CVEs entered the catalog. It is that the federal government is now formally distinguishing between vulnerability management (tracking CVEs) and breach management (confirming integrity before patching). Few private-sector teams currently have the tooling or process for the latter. For CISOs watching this space, BOD 26-04 is a template, not a regulation that applies only to the government. The expectation tends to flow downstream, much like how Microsoft's AI-discovered security fixes are already reshaping patch Tuesday routines across the industry.

Organizations using Check Point SmartConsole should immediately segment administrative access, review logs for unauthenticated activity, and apply any patches Check Point releases. SharePoint administrators should treat CVE-2026-50522 as a repeat of the June pattern and expedite patching. In both cases, CISA is asking for something harder than patching: they want proof that the patch arrived in time.

Get the tech essentials in 3 minutes every morning

One email, every weekday, with what actually matters in AI and tech.