Critical Authentication Bypass in Check Point SmartConsole and Deserialization Flaw in Microsoft SharePoint Added to CISA KEV Catalog
What Happened — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed two high‑severity vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog:
- CVE‑2026‑16232 – an authentication‑bypass flaw in Check Point SmartConsole (CVSS 9.3) that lets unauthenticated remote attackers obtain an admin login token.
- CVE‑2026‑50522 – a deserialization‑of‑untrusted‑data vulnerability in Microsoft SharePoint (CVSS 9.8) that permits authenticated users with Site Owner rights to execute arbitrary code.
Both flaws are confirmed to be under active exploitation, and the Check Point issue requires the management server to be reachable from the Internet with trusted‑client restrictions disabled.
Why It Matters for Compliance & Audit Readiness
- Unpatched third‑party flaws directly violate SOC 2 CC6.1 – System Operations and CC6.2 – Change Management requirements; evidence of timely patching is a core audit artifact.
- An authentication bypass in a security‑management console undermines CC3.1 – Logical Access Control and can invalidate the “least‑privilege” controls you must demonstrate.
- Continuous monitoring of vendor‑risk posture provides real‑time proof that you are addressing known exploited vulnerabilities, satisfying both CC1.1 – Risk Management and audit‑ready evidence collection.
Who Is Affected – Enterprises that run Check Point Security Management/Multi‑Domain servers or host Microsoft SharePoint sites—spanning finance, healthcare, government, and SaaS providers.
Recommended Actions
- Verify that all affected Check Point and SharePoint versions are patched to the July 2026 releases.
- Immediately block Internet access to management servers or enforce strict trusted‑client IP allow‑lists.
- Update your asset inventory and vendor‑risk register to flag these CVEs; map them to SOC 2 controls for evidence collection.
- Deploy continuous vulnerability‑scanning and integrate alerts into your SOC 2 evidence pipeline.
Source: Security Affairs
Technical Notes
- Check Point SmartConsole – CVE‑2026‑16232: Improper authentication; remote token theft; requires internet‑exposed management server and disabled Trusted‑Clients restrictions.
- Microsoft SharePoint – CVE‑2026‑50522: Deserialization of untrusted data; remote code execution via crafted payloads; exploited after public PoC release; patched in July 2026 Patch Tuesday.
Source: same as above