Skip to main content

Overview

Check Point has released a security advisory addressing a critical authentication bypass vulnerability in the SmartConsole login process for Security Management Server and Multi-Domain Management Server (MDS). This vulnerability could allow a remote, unauthenticated attacker to gain admin-level access by abusing application login tokens under certain configurations. Successful exploitation could result in unauthorised access to management systems, modification of security policies and configurations, compromise of administrative accounts, and reduced security visibility and control across affected environments. Check Point has confirmed that the vulnerability is being actively exploited, although the number of customers impacted is limited. 

  • CVE-2026-16232: Authentication Bypass Vulnerability (CVSSv3 9.1) 

Affected Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, and R82.10 

 

Canonical Ubuntu has released a security advisory addressing a high-severity local privilege escalation vulnerability in the snap-confine component of snapd. This vulnerability could allow a local, unprivileged attacker to bypass security restrictions and elevate their privileges through weaknesses in the initialisation of snap application sandboxes. Successful exploitation could lead to arbitrary code execution with root privileges, complete system compromise, unauthorised access to sensitive data, modification of system configurations, and full administrative control of the affected device. 

  • CVE-2026-8933: Local Privilege Escalation Vulnerability (CVSSv3 7.8) 

Affected Versions: 22.04 LTS, 24.04 LTS, and 26.04 LTS 

 

Microsoft has released security updates addressing two critical vulnerabilities in Microsoft SharePoint Server that have been actively exploited in the wild. These vulnerabilities could allow an unauthenticated, remote attack to send specially crafted data to a vulnerable SharePoint server and execute arbitrary code over the network. Successful exploitation could lead to complete compromise of the SharePoint environment, unauthorised access to sensitive information, deployment of malware or web shells, credential theft, lateral movement within the network, and persistent access to affected systems. 

  • CVE-2026-58644: Deserialisation of Untrusted Data vulnerability (CVSSv3 9.8) 

Affected Versions:  

  • Microsoft SharePoint Enterprise Server 2016 16.0.0 < 16.0.5556.1005 
  • Microsoft SharePoint Server 2019 16.0.0 < 16.0.10417.20153 
  • Microsoft SharePoint Server Subscription Edition 16.0.0 < 16.0.19725.20384. 
  • CVE-2026-50522: Deserialisation of Untrusted Data vulnerability (CVSSv3 9.8) 

Affected Versions:  

  • Microsoft SharePoint Enterprise Server 2016 16.0.0 < 16.0.5561.1001 
  • Microsoft SharePoint Server 2019 16.0.0 < 16.0.10417.20175 
  • Microsoft SharePoint Server Subscription Edition 16.0.0 < 16.0.19725.20434. 

 

F5 has released a security advisory addressing a critical vulnerability in NGINX Plus and NGINX Open Source. This vulnerability could allow a remote, unauthenticated attacker to send specially crafted HTTP requests that trigger memory corruption within the NGINX worker process when certain configurations are in use. Successful exploitation could lead to denial-of-service (DoS) conditions through worker process crashes or restarts and, in some circumstances, arbitrary code execution on affected systems, potentially resulting in unauthorised access and full compromise of the affected server. 

  • CVE-2026-42533: Heap-based Buffer Overflow vulnerability (CVSSv4 9.2) 

Affected Versions:  

  • NGINX Plus  
  • 37.0.0.1 < 37.0.3.1 
  • R36 < R36 P7 
  • R33 
  • NGINX Open Source  
  • 1.31.2 < 1.31.3 
  • 0.9.6 < 1.30.4

 

Recommended Action    

Organisations are encouraged to review the appropriate security advisory pages and apply the updates:

Check Point –Security Advisory | Check Point  

Ubuntu Security Advisory | Canonical Ubuntu  

Microsoft Security Update Guide | Microsoft  

F5 Security Advisory | F5  

If you have any concerns, or have been affected by a cyber-related issue, report it to us by submitting a Cyber Concerns Online Reporting Form.

Topics

  • Advisory
  • Vulnerability
  • Exploit
  • Patches and Updates