U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog.The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog.Below are the flaws added to the KeV catalog:CVE-2026-16232 (CVSS score of 9.3) Check Point SmartConsole Improper Authentication VulnerabilityCVE-2026-50522 (CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityThe first flaw added to the KeV catalog is a critical authentication bypass flaw, tracked as CVE-2026-16232, affecting Security Management and Multi-Domain Management (MDSM). The vulnerability, which is under active exploitation, allows unauthenticated remote attackers to obtain a SmartConsole login token and gain full administrative access.“An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers.” reads the advisory. “Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).”Successful exploitation requires the Management Server to be accessible from the internet and Trusted Clients (GUI client) access restrictions to be disabled.Check Point said it is aware of a limited number of customers targeted through CVE-2026-16232 and has already notified the affected organizations. The following attacker IP addresses have been identified as indicators of compromise (IoCs):151.241.99[.]207151.241.99[.]233158.62.198[.]182192.142.10[.]99139.28.37[.]250194.213.18[.]137The flaw impacts the following products and versions:Products: Security Management Server, Multi-Domain Security Management Server (MDS)Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10The second issue added to the catalog is a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522, that is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction, and stemming from the deserialization of untrusted data. CVE-2026-50522 was demonstrated live at Pwn2Own Berlin, meaning a working exploit was handed to Microsoft. Despite that, the advisory lists exploit maturity as unknown.Organizations should apply the available security updates immediately.watchTowr observed active exploitation of CVE-2026-50522 targeting on-premises Microsoft SharePoint servers shortly after public exploit code was released. Attackers are using the flaw to steal SharePoint machine keys in a single request, enabling persistent access even after patching. Security experts warn that organizations should not only apply Microsoft’s updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise.“On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability. Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.” watchTowr wrote on LinkedIn. “Attackers are pulling SharePoint machine keys via a single request. Patching is not enough, defenders should rotate credentials on any assets that may have been exposed.”Cybersecurity firm Defused Cyber also spotted threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload through a SharePoint sign-in endpoint. The observed attacks require no authentication, consistent with the vulnerability’s unauthenticated remote code execution profile.According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.CISA orders federal agencies to fix these flaws by July 25, 2026.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, CISA)