CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector Action
Summary
Hide ▲
Show ▼
CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25. The directive makes Binding Operational Directive (BOD) 26-04 immediately relevant for exposed management servers. The action turns an actively exploited flaw into a federal remediation deadline and increases pressure on other organizations to patch quickly.
Related Happenings
N-able security patch release for CVE-2026-18577
Security Patch Release
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
SmartConsole actively exploited authentication bypass (CVE-2026-16232)
Vulnerability
H score43
First: 23.07.2026 11:13
Last: 23.07.2026 11:13
Sources 1
How related:
"Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers."
About this happening:
Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products....
SmartConsole actively exploited authentication bypass (CVE-2026-16232)
VulnerabilityHow related: "Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers."
About this happening: Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products....
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector Action
H score35
First: 26.06.2026 22:43
Last: 26.06.2026 22:43
Sources 1
About this happening:
CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector Action
H score36
First: 16.06.2026 13:47
Last: 16.06.2026 13:47
Sources 1
About this happening:
CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector ActionAbout this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
Timeline
-
23.07.2026 11:13 1 articles · 13d ago
Check Point warns of exploited SmartConsole zero-day
Initial DisclosureCheck Point Software's SmartConsole GUI admin panel was exposed to an actively exploited zero-day tracked as CVE-2026-16232. The authentication bypass lets unauthenticated attackers obtain an application login token, authenticate with administrator privileges, and change security policies and security configurations on vulnerable Security Management Server and Multi-Domain Security Management Server deployments.
Show sources
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13
-
23.07.2026 11:13 2 articles · 13d ago
CISA orders patching for CVE-2026-16232
Legal Policy Action UpdateCISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25 under Binding Operational Directive (BOD) 26-04. The agency warned that the flaw is a frequent attack vector and urged organizations to prioritize patching.
Show sources
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13
- Check Point warns of SmartConsole zero-day exploited in attacks — www.bleepingcomputer.com — 23.07.2026 11:13