Check Point SmartConsole auth bypass gives attackers full admin
Check Point SmartConsole CVE-2026-16232 is a critical authentication bypass with a CVSS of 9.3, actively exploited and listed in CISA KEV. Patch your Security Management servers now.
4 stories tagged patching.
Check Point SmartConsole CVE-2026-16232 is a critical authentication bypass with a CVSS of 9.3, actively exploited and listed in CISA KEV. Patch your Security Management servers now.
wp2shell is a pre-authentication remote code execution chain in WordPress Core. Two CVEs let anonymous attackers run code on 6.9 and 7.0 sites with no plugins.
Bad Epoll (CVE-2026-46242) is a Linux epoll use-after-free giving unprivileged users root on v6.4+ kernels and Android. No workaround exists. Apply patch a6dc643c6931 now.
Splunk Enterprise flaw CVE-2026-20253 is under active exploitation. Patch by June 21 or disable the PostgreSQL sidecar safely.