Daily briefing · July 22, 2026
Check Point SmartConsole Auth Bypass Under Active Exploitation; Oracle Fusion Middleware Hit with Multiple Critical Flaws
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 22, 2026 closes as a relatively calm day by volume, but not without a serious standout: CVE-2026-16232, an authentication bypass in Check Point SmartConsole, carries confirmed active exploitation in CISA's KEV catalog and was armed the same day it was disclosed, giving defenders virtually no reaction window. Alongside it, Oracle Platform Security for Java absorbed a cluster of critical-severity vulnerabilities — two of them unauthenticated and rated 10.0 and 9.8 — published on the same day, making patch prioritization essential for Fusion Middleware environments.
Today’s brief
- KEV ALERT: Check Point SmartConsole auth bypass (CVE-2026-16232, CVSS 9.1) is under active exploitation — armed on day zero of disclosure, full admin takeover possible remotely.
- Oracle Fusion Middleware received four critical CVEs today, including a perfect CVSS 10.0 (CVE-2026-60366), all exploitable over HTTP with no authentication required in the worst cases.
- Fujitsu openFT (CVE-2026-16606) and Joomla Page Builder CK (CVE-2026-63048) both expose pre-auth or authenticated RCE paths that demand immediate attention.
- Brazil-focused ransomware activity remains intense: five Brazilian organizations confirmed as new victims today, with qilin, Doommageddon, unsafe, and nova all claiming targets across healthcare, retail, and services sectors.
Critical highlights
1
CVE-2026-16232KEVCVSS 9.1PoCsame dayaffects Multi-Domain Security Management An authentication bypass in Check Point SmartConsole allows a remote unauthenticated attacker to obtain an application login token and authenticate with full administrative privileges, enabling modification of security policies. This is the day's most urgent item: it is in CISA's KEV catalog, observed by VulnCheck as exploited in the wild, and was armed with a proof of concept on the very same day of disclosure — defenders with internet-exposed Management Servers must act immediately.
2
Rated CVSS 10.0, this flaw in Oracle Platform Security for Java (Fusion Middleware 12.2.1.4.0 and 14.1.2.0.0) allows an unauthenticated network attacker via HTTP to fully compromise the product; the impact extends beyond the vulnerable component itself, raising the blast radius considerably for Oracle middleware stacks.
3
A CVSS 9.9 vulnerability in the same Oracle Platform Security for Java component, this one exploitable by a low-privileged attacker over HTTP, can cascade impact to other Oracle products — any environment running the affected Fusion Middleware versions should treat this and its sibling CVEs as a cluster requiring unified patch action.
4
Another unauthenticated, network-exploitable critical flaw (CVSS 9.8) in Oracle Platform Security for Java's Centralized Thirdparty Jars component; the breadth of this vulnerability cluster in a single Oracle product line published on the same day signals a significant exposure window for Fusion Middleware operators.
5
A fourth critical CVE (CVSS 9.8) in Oracle Platform Security for Java, again unauthenticated and reachable via HTTP, reinforcing the need to treat July 22's Oracle Fusion Middleware advisories as a high-priority patching event rather than routine maintenance.
6
A SQL injection vulnerability (CVSS 9.8) in Xpoda's No Code Platform allows unauthenticated attackers to manipulate backend databases directly; the vendor did not respond to pre-disclosure contact, meaning no patch coordination occurred and users should verify vendor guidance independently before relying on any fix.
7
An authenticated arbitrary file upload vulnerability in the Page Builder CK extension for Joomla leads to remote code execution; even though authentication is required, Joomla environments with open registration or compromised editor accounts are effectively exposed to full server takeover.
8
Fujitsu Software Linux openFT and Oracle Solaris openFT before version 12.1D00 contain a pre-authentication remote code execution flaw, meaning an attacker with network access requires no credentials to run arbitrary code — a particularly severe exposure for legacy file transfer infrastructure still in production.
9
An open redirect in Unblu Spark escalates to DOM-based XSS when the product is deployed with embedded setup mode enabled, granting injected JavaScript full access to cookies, DOM, and same-origin resources of the host application — a meaningful session hijacking risk in customer-facing deployments.
10
When compute mode is explicitly enabled on a standalone MongoDB instance, insufficient validation of external BSON data during aggregation can cause memory corruption leading to process termination or unpredictable behavior; while non-default, any environment that has enabled this feature should prioritize patching given MongoDB's widespread deployment.
Ransomware today
Several Brazilian organizations have recently been confirmed as ransomware victims: Cpcg and PP+K were claimed by qilin, CCR Solutions (Business Services) by unsafe, Reni Farmácias Associadas (Healthcare) by Doommageddon, and Jota Joias Premium (Consumer Services) by the nova group. Over the past 30 days, the most active ransomware groups globally and in Brazil have been lockbit5, lockbit3, ransomhub, thegentlemen, 8base, and arcusmedia — all showing significant Brazilian victim counts, pointing to a sustained and targeted campaign against the country.
Cpcg BRqilin
CCR Solutions BRunsafe · Business Services
Reni Farmácias Associadas BRDoommageddon · Healthcare
PP+K BRqilin
Jota Joias Premium BRnova · Consumer Services
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actor groups are being tracked as active or recently updated, including blackshadow (attributed to Iran), coinbasecartel, kazu, kelvinsecurity, krybit, and apt73. None of these groups currently have confirmed known victims in the dataset, but their active status warrants monitoring, particularly blackshadow given its Iranian state-nexus and history of destructive operations.
Brazil focus
Brazil continues to be a heavily targeted environment: beyond the five new ransomware victims confirmed in recent days, the broader 30-day picture includes additional victims such as FMZ Tecnologia em Sistemas (Technology), guarnera.com.br (Business Services), and gruposelpe.com.br (Business Services) — with lockbit5 alone accounting for multiple Brazilian targets. The concentration across healthcare, technology, and business services sectors reflects adversaries deliberately pursuing Brazilian mid-market organizations with potentially weaker security postures.
Cpcgqilin
Jota Joias Premiumnova · Consumer Services
CCR Solutionsunsafe · Business Services
Reni Farmácias AssociadasDoommageddon · Healthcare
PP+Kqilin
FMZ Tecnologia em Sistemasnova · Technology
guarnera.com.brlockbit5 · Business Services
gruposelpe.com.brlockbit5 · Business Services
Today’s recommendation: Security teams should immediately prioritize patching or isolating internet-exposed Check Point Management Servers vulnerable to CVE-2026-16232, as active exploitation is confirmed with zero-day arming; in parallel, Fusion Middleware operators must apply Oracle's July 22 patches addressing the four Platform Security for Java critical CVEs before adversaries begin weaponizing them.
With both network-facing management infrastructure and middleware platforms under simultaneous pressure, now is the right moment to validate which of these exposed surfaces are reachable in your own environment before an attacker does it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →