CISA listed two Microsoft SharePoint deserialization flaws, CVE-2026-58644 and CVE-2026-50522, to the Known Exploited Vulnerabilities (KEV) list on 16 and 22 July. Both landed within a week of the agency's 14 July SharePoint hardening advisory.
Deserialization flaws let an attacker turn data the server unpacks into code it runs, a route that hands remote control of a collaboration platform many organisations expose to the internet. SharePoint has stayed on the active-exploitation list since the three-day patch deadline CISA set on 1 July , and two more entries in one week show the surface has not cooled.
Check Point's SmartConsole authentication flaw, CVE-2026-16232, joined the same 22 July batch. The week's additions widened the exposure across the collaboration and security-management tools that sit at the centre of enterprise networks, not Microsoft's platform alone.
