CiberLATAMbywhalemate

CISA Confirms SharePoint, Check Point Exploits

CISA added SharePoint and Check Point flaws to KEV as active exploitation continues. Latin America faces added pressure from ERP and firewall bugs.

Whalemate Labs · AI-assisted researchAug 4, 20263 min read

CVE Brief reported that CVE-2026-45659 in Microsoft Office SharePoint is being actively exploited in the wild, with CISA confirming it in the Known Exploited Vulnerabilities catalog. In parallel, Telefónica Tech said CVE-2026-16232 in Check Point SmartConsole is also under active exploitation, but only against a small set of customers.

CVE Brief reported that CVE-2026-45659 in Microsoft Office SharePoint is being actively exploited in the wild, and CISA has confirmed it through its Known Exploited Vulnerabilities catalog. The outlet described it as an active threat confirmed under real-world attack, which points to ongoing campaigns against vulnerable instances.

SharePoint and Check Point under confirmed exploitation

The same pattern appears in Telefónica Tech's weekly bulletin, which said Check Point confirmed active exploitation of CVE-2026-16232 in the SmartConsole authentication process. According to that notice, the impact was limited to a small number of customers that exposed management infrastructure directly and did not restrict Trusted Clients.

The picture drawn by these alerts expands with reference databases such as CVE Tools, which in July 2026 recorded 1.6K vulnerabilities with confirmed exploitation under CISA's KEV, and 17.1K total entries tied to the catalog. That list explicitly includes products such as Fortinet, Check Point, Oracle WebLogic, Hikvision, and SharePoint, marked as In CISA KEV and flagged for active exploitation.

Vulnpedia adds another layer of context by cross-referencing KEV CVEs with public PoCs, EPSS, and technical references. The site says it indexes more than 345,000 CVEs and lists 25 vulnerabilities marked as Known exploited in the last 45 days, a time window that helps identify the products most recently under exploitation, including firewalls, ERPs, and collaboration platforms.

Regional pressure on ERPs, firewalls, and collaboration tools

The risk is not limited to global catalogs. A regional analysis by Getup Cloud, based on the DBIR report, says that in Latin America and the Caribbean, vulnerability exploitation is the initial access vector in 44% of breaches, above the global average of 31%. The same work adds that in 2025, only 26% of critical vulnerabilities present in CISA's KEV were fully remediated by organizations.

That context is reflected in official notices and coordination efforts. INCIBE-CERT published early alerts on vulnerabilities in Fortinet security products, such as FortiSandbox, with descriptions of improper neutralization of special elements, mitigations, and fixed versions. It also coordinated the disclosure of CVE-2026-12895 in ERPNext, a high-severity SQL injection with a CVSS v4.0 score of 7.1, exploitable by an authenticated user and affecting versions earlier than 15.111.0 and 16.22.0.

The technical notice explains that the issue stems from string interpolation with str.format(), with an impact on confidential data and patches already recommended. In the same vein, Devel Group detailed CVE-2025-68686 in Fortinet FortiOS, saying exploitation requires the attacker to have previously compromised the device and gained access to the file system, and that it is carried out through specially crafted HTTP requests.

That analysis also recalls the deadline set by CISA under Binding Operational Directive 26-04 and operational recommendations such as removing management interfaces and VPN services from Internet exposure if patching cannot be completed on time.

The regional signal is rounded out by an article from Estamos en Línea about a cyberattack campaign targeting organizations in Latin America, where exploitation of vulnerabilities in critical infrastructure and exposed services appears as one of the main vectors. The combination of KEV catalogs, vendor alerts, and CERT advisories places ERPs, collaboration systems, firewalls, video surveillance, and industrial IoT at the center of monitoring.

Sources

View all