Check Point SmartConsole CVE-2026-16232: Admin Bypass

Check Point SmartConsole CVE-2026-16232: Admin Bypass

Check Point SmartConsole CVE-2026-16232 is now on CISA’s Known Exploited Vulnerabilities list: an unauthenticated attacker can forge a login token and get full administrator access to the console that manages an organization’s entire firewall fleet. Check Point patched it on July 22 and confirmed a handful of customers were already targeted. The federal remediation deadline…

Read More

wp2shell WordPress RCE: Patch Now

wp2shell WordPress RCE

wp2shell WordPress RCE is now a two-CVE chain in CISA’s Known Exploited Vulnerabilities catalog — and it lets a completely unauthenticated attacker execute code on a default WordPress install with no plugins involved. If you run self-hosted WordPress and haven’t confirmed the July 17 auto-update landed, check today. What Happened wp2shell WordPress RCE combines two…

Read More

CVE-2026-50522 SharePoint RCE: Patching Isn’t Enough

CVE-2026-50522 SharePoint RCE

CVE-2026-50522 SharePoint RCE is now the third actively exploited remote code execution flaw hitting Microsoft’s on-premises collaboration platform in three weeks — and this one lets attackers steal cryptographic machine keys that remain valid long after the server is patched. If you run SharePoint Server 2016, 2019, or Subscription Edition on-premises, patching is no longer…

Read More

Oracle E-Business Suite CVE-2026-46817 Actively Exploited

Oracle E-Business Suite CVE-2026-46817

Oracle E-Business Suite CVE-2026-46817, a critical flaw, is under active exploitation: an unauthenticated attacker with nothing more than HTTP access can take over Oracle Payments — the module that executes your payment runs. CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 15 and gave US federal agencies three days to fix…

Read More

SonicWall SMA1000 CVE-2026-15409 RCE: Patch by July 17

SonicWall SMA1000 CVE-2026-15409 RCE

SonicWall confirmed that the SonicWall SMA1000 CVE-2026-15409 RCE chain is being actively exploited: an unauthenticated attacker can force a target appliance into arbitrary requests, then pivot to full administrator-level command execution — no valid login required at any point. CISA added both flaws to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of…

Read More