Daily briefing · July 22, 2026
Check Point SmartConsole Auth Bypass Under Active Exploitation; Oracle Fusion Middleware Hit with Multiple Critical Flaws
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 22, 2026 closes as a relatively calm day by volume, but not without a serious standout: CVE-2026-16232, an authentication bypass in Check Point SmartConsole, carries confirmed active exploitation in CISA's KEV catalog and was armed the same day it was disclosed, giving defenders virtually no reaction window. Alongside it, Oracle Platform Security for Java absorbed a cluster of critical-severity vulnerabilities — two of them unauthenticated and rated 10.0 and 9.8 — published on the same day, making patch prioritization essential for Fusion Middleware environments.
Today’s brief
- KEV ALERT: Check Point SmartConsole auth bypass (CVE-2026-16232, CVSS 9.1) is under active exploitation — armed on day zero of disclosure, full admin takeover possible remotely.
- Oracle Fusion Middleware received four critical CVEs today, including a perfect CVSS 10.0 (CVE-2026-60366), all exploitable over HTTP with no authentication required in the worst cases.
- Fujitsu openFT (CVE-2026-16606) and Joomla Page Builder CK (CVE-2026-63048) both expose pre-auth or authenticated RCE paths that demand immediate attention.
- Brazil-focused ransomware activity remains intense: five Brazilian organizations confirmed as new victims today, with qilin, Doommageddon, unsafe, and nova all claiming targets across healthcare, retail, and services sectors.
Critical highlights
1
CVE-2026-16232KEVCVSS 9.1PoCsame dayaffects Multi-Domain Security Management An authentication bypass in Check Point SmartConsole allows a remote unauthenticated attacker to obtain an application login token and authenticate with full administrative privileges, enabling modification of security policies. This is the day's most urgent item: it is in CISA's KEV catalog, observed by VulnCheck as exploited in the wild, and was armed with a proof of concept on the very same day of disclosure — defenders with internet-exposed Management Servers must act immediately.
2
Rated CVSS 10.0, this flaw in Oracle Platform Security for Java (Fusion Middleware 12.2.1.4.0 and 14.1.2.0.0) allows an unauthenticated network attacker via HTTP to fully compromise the product; the impact extends beyond the vulnerable component itself, raising the blast radius considerably for Oracle middleware stacks.
3
A CVSS 9.9 vulnerability in the same Oracle Platform Security for Java component, this one exploitable by a low-privileged attacker over HTTP, can cascade impact to other Oracle products — any environment running the affected Fusion Middleware versions should treat this and its sibling CVEs as a cluster requiring unified patch action.
4
Another unauthenticated, network-exploitable critical flaw (CVSS 9.8) in Oracle Platform Security for Java's Centralized Thirdparty Jars component; the breadth of this vulnerability cluster in a single Oracle product line published on the same day signals a significant exposure window for Fusion Middleware operators.
5
A fourth critical CVE (CVSS 9.8) in Oracle Platform Security for Java, again unauthenticated and reachable via HTTP, reinforcing the need to treat July 22's Oracle Fusion Middleware advisories as a high-priority patching event rather than routine maintenance.
6
A SQL injection vulnerability (CVSS 9.8) in Xpoda's No Code Platform allows unauthenticated attackers to manipulate backend databases directly; the vendor did not respond to pre-disclosure contact, meaning no patch coordination occurred and users should verify vendor guidance independently before relying on any fix.
7
An authenticated arbitrary file upload vulnerability in the Page Builder CK extension for Joomla leads to remote code execution; even though authentication is required, Joomla environments with open registration or compromised editor accounts are effectively exposed to full server takeover.
8
Fujitsu Software Linux openFT and Oracle Solaris openFT before version 12.1D00 contain a pre-authentication remote code execution flaw, meaning an attacker with network access requires no credentials to run arbitrary code — a particularly severe exposure for legacy file transfer infrastructure still in production.
9
An open redirect in Unblu Spark escalates to DOM-based XSS when the product is deployed with embedded setup mode enabled, granting injected JavaScript full access to cookies, DOM, and same-origin resources of the host application — a meaningful session hijacking risk in customer-facing deployments.
10
When compute mode is explicitly enabled on a standalone MongoDB instance, insufficient validation of external BSON data during aggregation can cause memory corruption leading to process termination or unpredictable behavior; while non-default, any environment that has enabled this feature should prioritize patching given MongoDB's widespread deployment.
Ransomware today
Several Brazilian organizations have recently been confirmed as ransomware victims: Cpcg and PP+K were claimed by qilin, CCR Solutions (Business Services) by unsafe, Reni Farmácias Associadas (Healthcare) by Doommageddon, and Jota Joias Premium (Consumer Services) by the nova group. Over the past 30 days, the most active ransomware groups globally and in Brazil have been lockbit5, lockbit3, ransomhub, thegentlemen, 8base, and arcusmedia — all showing significant Brazilian victim counts, pointing to a sustained and targeted campaign against the country.
Cpcg BRqilin
CCR Solutions BRunsafe · Business Services
Reni Farmácias Associadas BRDoommageddon · Healthcare
PP+K BRqilin
Jota Joias Premium BRnova · Consumer Services
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actor groups are being tracked as active or recently updated, including blackshadow (attributed to Iran), coinbasecartel, kazu, kelvinsecurity, krybit, and apt73. None of these groups currently have confirmed known victims in the dataset, but their active status warrants monitoring, particularly blackshadow given its Iranian state-nexus and history of destructive operations.
Brazil focus
Brazil continues to be a heavily targeted environment: beyond the five new ransomware victims confirmed in recent days, the broader 30-day picture includes additional victims such as FMZ Tecnologia em Sistemas (Technology), guarnera.com.br (Business Services), and gruposelpe.com.br (Business Services) — with lockbit5 alone accounting for multiple Brazilian targets. The concentration across healthcare, technology, and business services sectors reflects adversaries deliberately pursuing Brazilian mid-market organizations with potentially weaker security postures.
Cpcgqilin
Jota Joias Premiumnova · Consumer Services
CCR Solutionsunsafe · Business Services
Reni Farmácias AssociadasDoommageddon · Healthcare
PP+Kqilin
FMZ Tecnologia em Sistemasnova · Technology
guarnera.com.brlockbit5 · Business Services
gruposelpe.com.brlockbit5 · Business Services
Today’s recommendation: Security teams should immediately prioritize patching or isolating internet-exposed Check Point Management Servers vulnerable to CVE-2026-16232, as active exploitation is confirmed with zero-day arming; in parallel, Fusion Middleware operators must apply Oracle's July 22 patches addressing the four Platform Security for Java critical CVEs before adversaries begin weaponizing them.
With both network-facing management infrastructure and middleware platforms under simultaneous pressure, now is the right moment to validate which of these exposed surfaces are reachable in your own environment before an attacker does it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →