🚨 CRITICAL ALERT: Active Zero-Day Exploits

Two critical vulnerabilities with CVSS scores above 8.0 are currently in the CISA Known Exploited Vulnerabilities catalog and should be treated as immediate exposure events. One affects Microsoft Office SharePoint and enables unauthenticated remote code execution, while the other affects Check Point SmartConsole and can grant a remote attacker full administrative access if successfully exploited. Both require urgent patching and exposure reduction now.[1][3]

Critical Vulnerabilities (CVSS >= 8.0)

  • CVE-2026-50522 (CVSS: 9.8): Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. This flaw affects on-premises SharePoint Server deployments and is being actively exploited in the wild. View NVD | CISA KEV
  • CVE-2026-16232 (CVSS: 9.1): An authentication bypass in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Check Point states this vulnerability is being exploited and has affected a very small number of customers. View NVD | CISA KEV

⚡ Immediate Actions Required

Patch immediately for all affected Microsoft SharePoint and Check Point environments, starting with any internet-exposed systems.[3][4] If patching cannot be completed at once, restrict external access to SharePoint servers and Management Server IP addresses, enforce trusted-client restrictions where available, and segment management interfaces from the public internet.[3][4]

Assume active exploitation risk and review logs for suspicious authentication, unexpected administrative token use, abnormal SharePoint deserialization activity, or new/unknown process execution on affected hosts.[2][3][4] Prioritize containment, verify configuration hardening, and validate that the latest vendor fixes are deployed across all reachable instances.[3][4]