Daily briefing · July 22, 2026

Check Point SmartConsole Auth Bypass Under Active Exploitation; Oracle Fusion Middleware Hit with Multiple Critical Flaws

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

July 22, 2026 closes as a relatively calm day by volume, but not without a serious standout: CVE-2026-16232, an authentication bypass in Check Point SmartConsole, carries confirmed active exploitation in CISA's KEV catalog and was armed the same day it was disclosed, giving defenders virtually no reaction window. Alongside it, Oracle Platform Security for Java absorbed a cluster of critical-severity vulnerabilities — two of them unauthenticated and rated 10.0 and 9.8 — published on the same day, making patch prioritization essential for Fusion Middleware environments.

Today’s brief
  • KEV ALERT: Check Point SmartConsole auth bypass (CVE-2026-16232, CVSS 9.1) is under active exploitation — armed on day zero of disclosure, full admin takeover possible remotely.
  • Oracle Fusion Middleware received four critical CVEs today, including a perfect CVSS 10.0 (CVE-2026-60366), all exploitable over HTTP with no authentication required in the worst cases.
  • Fujitsu openFT (CVE-2026-16606) and Joomla Page Builder CK (CVE-2026-63048) both expose pre-auth or authenticated RCE paths that demand immediate attention.
  • Brazil-focused ransomware activity remains intense: five Brazilian organizations confirmed as new victims today, with qilin, Doommageddon, unsafe, and nova all claiming targets across healthcare, retail, and services sectors.
14
critical
1
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-16232KEVCVSS 9.1PoCsame dayaffects Multi-Domain Security Management
An authentication bypass in Check Point SmartConsole allows a remote unauthenticated attacker to obtain an application login token and authenticate with full administrative privileges, enabling modification of security policies. This is the day's most urgent item: it is in CISA's KEV catalog, observed by VulnCheck as exploited in the wild, and was armed with a proof of concept on the very same day of disclosure — defenders with internet-exposed Management Servers must act immediately.
2
CVE-2026-60366CVSS 10affects Oracle Platform Security for Java
Rated CVSS 10.0, this flaw in Oracle Platform Security for Java (Fusion Middleware 12.2.1.4.0 and 14.1.2.0.0) allows an unauthenticated network attacker via HTTP to fully compromise the product; the impact extends beyond the vulnerable component itself, raising the blast radius considerably for Oracle middleware stacks.
3
CVE-2026-60369CVSS 9.9affects Oracle Platform Security for Java
A CVSS 9.9 vulnerability in the same Oracle Platform Security for Java component, this one exploitable by a low-privileged attacker over HTTP, can cascade impact to other Oracle products — any environment running the affected Fusion Middleware versions should treat this and its sibling CVEs as a cluster requiring unified patch action.
4
CVE-2026-60372CVSS 9.8affects Oracle Platform Security for Java
Another unauthenticated, network-exploitable critical flaw (CVSS 9.8) in Oracle Platform Security for Java's Centralized Thirdparty Jars component; the breadth of this vulnerability cluster in a single Oracle product line published on the same day signals a significant exposure window for Fusion Middleware operators.
5
CVE-2026-60367CVSS 9.8affects Oracle Platform Security for Java
A fourth critical CVE (CVSS 9.8) in Oracle Platform Security for Java, again unauthenticated and reachable via HTTP, reinforcing the need to treat July 22's Oracle Fusion Middleware advisories as a high-priority patching event rather than routine maintenance.
6
CVE-2026-2395CVSS 9.8affects No Code Platform
A SQL injection vulnerability (CVSS 9.8) in Xpoda's No Code Platform allows unauthenticated attackers to manipulate backend databases directly; the vendor did not respond to pre-disclosure contact, meaning no patch coordination occurred and users should verify vendor guidance independently before relying on any fix.
7
CVE-2026-63048CVSS 9.4affects Page Builder CK extension for Joomla
An authenticated arbitrary file upload vulnerability in the Page Builder CK extension for Joomla leads to remote code execution; even though authentication is required, Joomla environments with open registration or compromised editor accounts are effectively exposed to full server takeover.
8
CVE-2026-16606CVSS 9.3affects Linux openFT
Fujitsu Software Linux openFT and Oracle Solaris openFT before version 12.1D00 contain a pre-authentication remote code execution flaw, meaning an attacker with network access requires no credentials to run arbitrary code — a particularly severe exposure for legacy file transfer infrastructure still in production.
9
CVE-2026-8152CVSS 9.3affects Unblu Spark
An open redirect in Unblu Spark escalates to DOM-based XSS when the product is deployed with embedded setup mode enabled, granting injected JavaScript full access to cookies, DOM, and same-origin resources of the host application — a meaningful session hijacking risk in customer-facing deployments.
10
CVE-2026-13072CVSS 9.2affects MongoDB Server
When compute mode is explicitly enabled on a standalone MongoDB instance, insufficient validation of external BSON data during aggregation can cause memory corruption leading to process termination or unpredictable behavior; while non-default, any environment that has enabled this feature should prioritize patching given MongoDB's widespread deployment.
Ransomware today

Several Brazilian organizations have recently been confirmed as ransomware victims: Cpcg and PP+K were claimed by qilin, CCR Solutions (Business Services) by unsafe, Reni Farmácias Associadas (Healthcare) by Doommageddon, and Jota Joias Premium (Consumer Services) by the nova group. Over the past 30 days, the most active ransomware groups globally and in Brazil have been lockbit5, lockbit3, ransomhub, thegentlemen, 8base, and arcusmedia — all showing significant Brazilian victim counts, pointing to a sustained and targeted campaign against the country.

Cpcg BRqilin
CCR Solutions BRunsafe · Business Services
Reni Farmácias Associadas BRDoommageddon · Healthcare
PP+K BRqilin
Jota Joias Premium BRnova · Consumer Services
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actor groups are being tracked as active or recently updated, including blackshadow (attributed to Iran), coinbasecartel, kazu, kelvinsecurity, krybit, and apt73. None of these groups currently have confirmed known victims in the dataset, but their active status warrants monitoring, particularly blackshadow given its Iranian state-nexus and history of destructive operations.

Brazil focus

Brazil continues to be a heavily targeted environment: beyond the five new ransomware victims confirmed in recent days, the broader 30-day picture includes additional victims such as FMZ Tecnologia em Sistemas (Technology), guarnera.com.br (Business Services), and gruposelpe.com.br (Business Services) — with lockbit5 alone accounting for multiple Brazilian targets. The concentration across healthcare, technology, and business services sectors reflects adversaries deliberately pursuing Brazilian mid-market organizations with potentially weaker security postures.

Cpcgqilin
Jota Joias Premiumnova · Consumer Services
CCR Solutionsunsafe · Business Services
Reni Farmácias AssociadasDoommageddon · Healthcare
PP+Kqilin
FMZ Tecnologia em Sistemasnova · Technology
guarnera.com.brlockbit5 · Business Services
gruposelpe.com.brlockbit5 · Business Services
Today’s recommendation: Security teams should immediately prioritize patching or isolating internet-exposed Check Point Management Servers vulnerable to CVE-2026-16232, as active exploitation is confirmed with zero-day arming; in parallel, Fusion Middleware operators must apply Oracle's July 22 patches addressing the four Platform Security for Java critical CVEs before adversaries begin weaponizing them.
With both network-facing management infrastructure and middleware platforms under simultaneous pressure, now is the right moment to validate which of these exposed surfaces are reachable in your own environment before an attacker does it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share