Multiple zero-day exploits in enterprise security tools

Check Point's SmartConsole GUI admin panel has an actively exploited zero-day authentication bypass (CVE-2026-16232, CVSS 9.3) that grants full admin access to Security Management servers; a patch has been released. Cisco's Secure FMC also faces an actively exploited zero-day involving static credentials.

38 reports · 36 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🤖 CVE-2026-16232 (CVSS 9.3): Check Point SmartConsole auth bypass zero-day actively exploited in the wild. Allows full admin access to Security Management servers. Patch released. 🔗 https://www. ble

mastodon:infosec-exchangeother68d ago kagi ↗

🤖 CVE-2026-16232 (CVSS 9.3): Check Point SmartConsole auth bypass zero-day actively exploited in the wild. Allows full admin access to Security Management servers. Patch released. 🔗 https://www. bleepingcomputer.com/news/secu rity/check-point-patches-smartconsole-zero-day-exploited-in-attacks/ # CVE # 0day # CyberSec

🔒 Security News Digest - 2026-07-23 📊 5 updates from 3 sources: 🔹 The Hacker News: Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access https:// thehackernews.com/2026/07/chec

mastodon:infosec-exchangeother68d ago kagi ↗

🔒 Security News Digest - 2026-07-23 📊 5 updates from 3 sources: 🔹 The Hacker News: Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access https:// thehackernews.com/2026/07/chec k-point-patches-exploited.html 🔹 darkreading: Brazilian Banking Trojan Actively Spreading in Portugal https://www. darkreading.com/cyberattacks-d ata-breaches/brazilian-banking-trojan-spreading-port

🏆 New Achievement! Third Time's the Charm Point! SYSTEM LOG: Check Point Security Management and Multi-Domain Management have registered CVE-2026-16232, a critical zero-day, as actively exploited in

mastodon:infosec-exchangeother68d ago kagi ↗

🏆 New Achievement! Third Time's the Charm Point! SYSTEM LOG: Check Point Security Management and Multi-Domain Management have registered CVE-2026-16232, a critical zero-day, as actively exploited in production environments. This is the third Check Point vulnerability added to CISA's Known Exploited Vulnerabilities list this cycle, following CVE-2026-50751 in May and CVE-2024-24919 before that. Ex

🔵 THREAT INTELLIGENCE Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access Vulnerability | CRITICAL CVEs: CVE-2026-16232 Israeli cybersecurity firm Check Point Software has addr

mastodon:infosec-exchangeother68d ago kagi ↗

🔵 THREAT INTELLIGENCE Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access Vulnerability | CRITICAL CVEs: CVE-2026-16232 Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user... Full analysis: https://www. yazoul.net/news/article/check- point-patches-exploited-smartconsole-flaw-allowing-

🚨🔓 SIGINT // Cybersecurity Watch — 2026-07-26 New Check Point zero-day vulnerability confirmed exploited in the wild — patch immediately. https://www. securityweek.com/new-check-poi nt-zero-day-vuln

mastodon:fosstodonother66d ago kagi ↗

🚨🔓 SIGINT // Cybersecurity Watch — 2026-07-26 New Check Point zero-day vulnerability confirmed exploited in the wild — patch immediately. https://www. securityweek.com/new-check-poi nt-zero-day-vulnerability-exploited-in-the-wild/ # CVE # InfoSec # ZeroDay # Cybersecurity

Apple releases iOS 26.3 to fix CVE-2026-20700, a zero-day in the dyld component actively exploited in targeted attacks. Users should update immediately. # Cybersecurity # InfoSec https:// deafnews.it/

mastodon:infosec-exchangeother64d ago kagi ↗

Apple releases iOS 26.3 to fix CVE-2026-20700, a zero-day in the dyld component actively exploited in targeted attacks. Users should update immediately. # Cybersecurity # InfoSec https:// deafnews.it/en/article/apple-p atches-ios-26-dyld-zero-day-targeted-attacks-already-underway

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. https://www. bleepingcomputer.com/n

mastodon:infosec-exchangeother64d ago kagi ↗

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. https://www. bleepingcomputer.com/news/secu rity/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/

Arista patches VeloCloud Orchestrator zero-day exploited in attacks https://www. bleepingcomputer.com/news/secu rity/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/?utm_source=dlv

mastodon:infosec-exchangeother64d ago kagi ↗

Arista patches VeloCloud Orchestrator zero-day exploited in attacks https://www. bleepingcomputer.com/news/secu rity/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D

Arista fixes exploited VeloCloud Orchestrator zero-day Critical command-injection flaw in on-prem deployments patched after attacks https:// hostingpaper.com/article/arist a-fixes-exploited-velocloud-

mastodon:mstdn-socialother63d ago kagi ↗

Arista fixes exploited VeloCloud Orchestrator zero-day Critical command-injection flaw in on-prem deployments patched after attacks https:// hostingpaper.com/article/arist a-fixes-exploited-velocloud-orchestrator-zero-day # Security # Vulnerabilities

🤖 Arista patches VeloCloud Orchestrator zero-day (max severity) actively exploited in attacks. Command injection in on-prem deployments enables unauthenticated RCE. Patch now. 🔗 https://www. bleepin

mastodon:infosec-exchangeother63d ago kagi ↗

🤖 Arista patches VeloCloud Orchestrator zero-day (max severity) actively exploited in attacks. Command injection in on-prem deployments enables unauthenticated RCE. Patch now. 🔗 https://www. bleepingcomputer.com/news/secu rity/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/ # CVE # 0day # CyberSec

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

stream:bsky-jetstreamother63d ago kagi ↗

Arista VeloCloud Orchestratorの脆弱性がゼロデイ攻撃に悪用。オンプレミス展開でOSコマンドインジェクションが可能になり、攻撃者は特権内部機能にアクセスできる。 Hackers have been exploiting a critical OS injection vulnerability in Arista VeloCloud Orchestrator as a zero-day.

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator

mastodon:infosec-exchangeother63d ago kagi ↗

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices. **Make sure all VeloClo

🔒 Security News Digest - 2026-07-28 📊 6 updates from 2 sources: 🔹 SecurityWeek: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day https://www. securityweek.com/critical-ari

mastodon:infosec-exchangeother63d ago kagi ↗

🔒 Security News Digest - 2026-07-28 📊 6 updates from 2 sources: 🔹 SecurityWeek: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day https://www. securityweek.com/critical-aris ta-velocloud-orchestrator-vulnerability-exploited-as-zero-day/ 🔹 SecurityWeek: Unpatched Fastjson Vulnerability Exploited in Attacks https://www. securityweek.com/unpatched-fas tjson-vulnerability-

⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole 🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Manage

mastodon:infosec-exchangeother63d ago kagi ↗

⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole 🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be… 🔗 https:// hackmag.com/news/cve-2026-1

🚨 SIGINT // Cybersecurity Watch — 2026-07-29 Critical Arista VeloCloud Orchestrator vulnerability exploited as a zero-day, threatening SD-WAN infrastructure worldwide. https://www. securityweek.com/c

mastodon:fosstodonother63d ago kagi ↗

🚨 SIGINT // Cybersecurity Watch — 2026-07-29 Critical Arista VeloCloud Orchestrator vulnerability exploited as a zero-day, threatening SD-WAN infrastructure worldwide. https://www. securityweek.com/critical-aris ta-velocloud-orchestrator-vulnerability-exploited-as-zero-day/ # CVE # ZeroDay # InfoSec # Cybersecurity

CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available. # CheckPoint # SmartConsole # CVE202616232 # Authenti

mastodon:infosec-exchangeother62d ago kagi ↗

CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available. # CheckPoint # SmartConsole # CVE202616232 # AuthenticationBypass # ZeroDay # CyberSecurity https:// securityonline.info/check-poin t-smartconsole-cve-2026-16232-2/?utm_source=mastodon&utm_medium=jetpack_social

🤖 CVE-2026-16232 (CVSS 9.3): Critical auth bypass in Check Point SmartConsole, actively exploited in the wild. Rapid7 released a PoC. Unauthenticated attackers can bypass authentication on Security M

mastodon:infosec-exchangeother62d ago kagi ↗

🤖 CVE-2026-16232 (CVSS 9.3): Critical auth bypass in Check Point SmartConsole, actively exploited in the wild. Rapid7 released a PoC. Unauthenticated attackers can bypass authentication on Security Management Servers. 🔗 https:// thehackernews.com/2026/07/rapi d7-releases-poc-for-exploited-check.html # CVE # CyberSec # InfoSec # Exploit # 0day

🤖 CVE-2026-20316: Cisco FMC static credential flaw exploited in zero-day attacks. The high-severity vulnerability allows unauthenticated access to Secure Firewall Management Center devices. Actively

mastodon:infosec-exchangeother62d ago kagi ↗

🤖 CVE-2026-20316: Cisco FMC static credential flaw exploited in zero-day attacks. The high-severity vulnerability allows unauthenticated access to Secure Firewall Management Center devices. Actively exploited in the wild. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/ # CVE # Cisco # ZeroDay # CyberSec

🏆 New Achievement! Zero-Day Lootbox: Security Edition! TERMS AND CONDITIONS APPLY. By operating Check Point SmartConsole, you have entered our Zero-Day Sweepstakes. Prizes are distributed randomly an

mastodon:infosec-exchangeother61d ago kagi ↗

🏆 New Achievement! Zero-Day Lootbox: Security Edition! TERMS AND CONDITIONS APPLY. By operating Check Point SmartConsole, you have entered our Zero-Day Sweepstakes. Prizes are distributed randomly and may include: unauthorized changes to your security configurations, courtesy of an unknown threat actor currently exercising this actively exploited flaw. Odds of receiving a patch before exploitatio

Cisco discloses actively exploited zero-day CVE-2026-20316 in FMC Software. CISA orders federal agencies to remediate by August 1 under BOD 26-04. https:// deafnews.it/en/article/cisco-f mc-cve-2026-2

mastodon:infosec-exchangeother61d ago kagi ↗

Cisco discloses actively exploited zero-day CVE-2026-20316 in FMC Software. CISA orders federal agencies to remediate by August 1 under BOD 26-04. https:// deafnews.it/en/article/cisco-f mc-cve-2026-20316-actively-exploited-zero-day-cisa-sets-august-1-deadline

🔹 The Hacker News Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly dis

mastodon:infosec-exchangeother61d ago kagi ↗

🔹 The Hacker News Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerabilit

🔒 Security News Digest - 2026-07-30 📊 8 updates from 3 sources: 🔹 SecurityWeek: Cisco Secure FMC Zero-Day Exploited in the Wild https://www. securityweek.com/cisco-secure- fmc-zero-day-exploited-in

mastodon:infosec-exchangeother61d ago kagi ↗

🔒 Security News Digest - 2026-07-30 📊 8 updates from 3 sources: 🔹 SecurityWeek: Cisco Secure FMC Zero-Day Exploited in the Wild https://www. securityweek.com/cisco-secure- fmc-zero-day-exploited-in-the-wild/ 🔹 The Hacker News: FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks https:// thehackernews.com/2026/07/fcc- blocks-new-foreign-produced-robots.html 🔹 The Hacker

Cisco FMC static credential vulnerability exploited as a zero-day L: https:// sec.cloudapps.cisco.com/securi ty/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh C: https:// news.y

mastodon:mstdn-socialother61d ago kagi ↗

Cisco FMC static credential vulnerability exploited as a zero-day L: https:// sec.cloudapps.cisco.com/securi ty/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh C: https:// news.ycombinator.com/item?id=4 9107382 posted on 2026.07.30 at 04:33:39 (c=0, p=3)

Cisco warns of FMC static credential flaw exploited in zero-day attacks https://www. bleepingcomputer.com/news/secu rity/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/ Cisco

mastodon:infosec-exchangeother61d ago kagi ↗

Cisco warns of FMC static credential flaw exploited in zero-day attacks https://www. bleepingcomputer.com/news/secu rity/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/ Cisco disclosed that CVE-2026-20316, a static-credential vulnerability in Secure Firewall Management Center (FMC) Software, has been actively exploited in zero-day attacks. The flaw allows an unauthenticate