CiberLATAMbywhalemate

CISA Confirms SharePoint, Check Point Exploits

CISA added SharePoint and Check Point flaws to KEV as active exploitation continues. Latin America faces added pressure from ERP and firewall bugs.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

CVE Brief reported that CVE-2026-45659 in Microsoft Office SharePoint is being actively exploited in the wild, with CISA confirming it in the Known Exploited Vulnerabilities catalog. In parallel, Telefónica Tech said CVE-2026-16232 in Check Point SmartConsole is also under active exploitation, but only against a small set of customers.

CVE Brief reported that CVE-2026-45659 in Microsoft Office SharePoint is being actively exploited in the wild, and CISA has confirmed it in the Known Exploited Vulnerabilities catalog. The outlet described it as an active threat confirmed under real-world attack, which points to ongoing campaigns against vulnerable instances.

What does the tracking show for SharePoint and Check Point?

The same pattern appears in Telefónica Tech's weekly bulletin, which said Check Point confirmed active exploitation of CVE-2026-16232 in the SmartConsole authentication process. According to that notice, the impact was limited to a small number of customers that exposed their management infrastructure directly and did not restrict Trusted Clients.

The broader picture comes into focus through reference databases such as CVE Tools, which in July 2026 recorded 1.6K vulnerabilities with confirmed exploitation under CISA's KEV program and 17.1K total entries tied to the catalog. That list explicitly includes products such as Fortinet, Check Point, Oracle WebLogic, Hikvision and SharePoint marked as In CISA KEV and flagged for active exploitation.

Vulnpedia adds another layer of context by cross-referencing CVEs in KEV with public PoCs, EPSS and technical references. The site says it has indexed more than 345,000 CVEs and identified 25 vulnerabilities marked as known exploited in the last 45 days, a window that helps show which products are under the most recent exploitation, including firewalls, ERPs and collaboration platforms.

Where is regional pressure concentrated on ERPs, firewalls and collaboration?

The risk is not limited to global catalogs. A regional analysis by Getup Cloud, based on the DBIR report, says that in Latin America and the Caribbean, vulnerability exploitation is the initial access vector in 44% of breaches, above the global average of 31%. The same study adds that in 2025 only 26% of critical vulnerabilities present in CISA's KEV were fully remediated by organizations.

That context is reflected in official advisories and coordination notices. INCIBE-CERT published early alerts on vulnerabilities in Fortinet security products, such as FortiSandbox, with descriptions of improper neutralization of special elements, mitigations and fixed versions. It also coordinated the disclosure of CVE-2026-12895 in ERPNext, a high-severity SQL injection with a CVSS v4.0 score of 7.1, exploitable by an authenticated user and affecting versions earlier than 15.111.0 and 16.22.0.

The technical notice explains that the flaw stems from string interpolation with str.format(), with an impact on confidential data and patches already recommended. In the same vein, Devel Group detailed that exploitation of CVE-2025-68686 in Fortinet FortiOS requires the attacker to have previously compromised the device and gained access to the file system, and that it is carried out through specially crafted HTTP requests.

That analysis also cites the deadline set by CISA under Binding Operational Directive 26-04, along with operational guidance such as removing management interfaces and VPN services from Internet exposure if patching cannot be completed in time.

The regional signal is rounded out by an article from Estamos en Línea about a cyberattack campaign targeting organizations in Latin America, where exploitation of vulnerabilities in critical infrastructure and exposed services appears as one of the main vectors. The combination of KEV catalogs, vendor alerts and CERT advisories places ERPs, collaboration systems, firewalls, video surveillance and industrial IoT at the center of current monitoring.

Sources

View all