Check Point SmartConsole CVE-2026-16232 is being exploited now
The lead today is CVE-2026-16232, an improper authentication flaw in Check Point SmartConsole rated CVSS 9.1. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-22, and SecurityWeek, BleepingComputer, and Rapid7 all confirm active exploitation in the wild. Check Point has released patches.
SmartConsole is the management interface for Check Point gateways. An authentication bypass here is not a low-stakes bug: it puts the control plane of your perimeter in reach. Because this one is KEV listed and confirmed exploited, it moves from patch eventually to patch now. Rapid7's writeup also flags related IDs including CVE-2026-62144, CVE-2026-62145, CVE-2026-50751, and the older CVE-2024-24919, so review your Check Point advisory coverage as a set rather than a single fix.
New KEV additions and the SharePoint picture
Alongside Check Point, CISA added CVE-2026-50522, a Microsoft SharePoint deserialization of untrusted data vulnerability, to KEV on 2026-07-22. It shows up in the hot list as a critical remote code execution issue at CVSS 9.8 with an EPSS score around 0.21. If you run on-premises SharePoint Server, treat this as an active exploitation item and confirm your build is patched.
Two other SharePoint entries are worth tracking even though they are not yet KEV listed: CVE-2026-55040, a security feature bypass at CVSS 9.8, and CVE-2026-45504, an Exchange elevation of privilege at CVSS 8.8. Exchange spoofing bug CVE-2026-42897 (CVSS 8.8) is already on KEV. Adobe ColdFusion path traversal CVE-2026-48282 remains the top hot mover at CVSS 10 and is KEV listed.
What the press adds: Zimbra and Linux root
Dark Reading and CISA advisory AA26-204A report a Russian state-supported phishing campaign exploiting a Zimbra Collaboration Suite zero-day against targets in the US and Ukraine. Australia's ASD and National Cyber Security Coordinator issued a matching warning about an ongoing Russian phishing campaign. If you run Zimbra, review the CISA advisory guidance and hunt for the described activity.
On Linux, Qualys and BleepingComputer detail RefluXFS, tracked as CVE-2026-64600, a kernel XFS local privilege escalation to root. Qualys also published CVE-2026-8933, a snap-confine local privilege escalation. These are local escalation issues, so prioritize them where untrusted users have shell access.
ICS advisories worth a glance
CISA released a batch of ICS advisories on 2026-07-23 covering Rockwell Automation ThinManager, Johnson Controls C-CURE 9000 and Victor application server, Johnson Controls XAAP Android, Panduit IntraVUE, and MZ Automation lib60870 and libIEC61850. If any of these run in your environment, pull the specific advisory and check affected versions.
Do this first
Work from confirmed exploitation down to the local escalation cleanup.
- Patch Check Point SmartConsole for CVE-2026-16232 today; it is KEV listed and exploited in the wild.
- Patch on-premises SharePoint for CVE-2026-50522, also newly KEV listed, and check CVE-2026-55040 and Exchange CVE-2026-42897.
- Confirm ColdFusion is patched for CVE-2026-48282, still the top hot mover at CVSS 10.
- Review the Zimbra zero-day advisory and hunt for the Russian phishing activity described in AA26-204A.
- Schedule the Linux fixes for CVE-2026-64600 and CVE-2026-8933 where untrusted local access exists.
Check your own patch state
To confirm where you stand on the Microsoft items, the free Microsoft Patch Tracker in Siemserva by Senserva ranks open patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions like CVE-2026-16232 daily. Siemserva also offers three free unlimited audits of your Microsoft 365, Intune, Defender, and Entra ID environment so you can validate coverage after today's fixes.
Sources
- SecurityWeek: New Check Point Zero-Day Vulnerability Exploited in the Wild (2026-07-23)
- BleepingComputer: Check Point warns of SmartConsole zero-day exploited in attacks (2026-07-23)
- Rapid7: CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild (2026-07-23)
- Dark Reading: Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets (2026-07-23)
- CISA Cybersecurity Advisories: Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite (2026-07-23)
- defenceconnect.com.au: ASD, National Cyber Security Coordinator warn of ongoing Russian phishing campaign - defenceconnect.com.au (2026-07-24)
- BleepingComputer: New RefluXFS Linux flaw lets attackers gain root privileges (2026-07-23)
- Qualys: RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) (2026-07-22)
- Qualys: CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine (2026-07-21)
- CISA Cybersecurity Advisories: Rockwell Automation ThinManager (2026-07-23)
- CISA Cybersecurity Advisories: Johnson Controls C-CURE 9000 and Victor application server (2026-07-23)
- CISA Cybersecurity Advisories: Panduit IntraVUE (2026-07-23)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-24.