Breaking: SharePoint RCE + Check Point Admin Bypass + Qilin Ransomware via Palo Alto VPN — 23 July 2026
Three Critical Infrastructure Attacks: SharePoint RCE, Check Point Admin Bypass, and Qilin Ransomware via Palo Alto VPN
CISA added two new entries to the Known Exploited Vulnerabilities catalog on July 22, both with confirmed active exploitation and three-day remediation deadlines. Separately, Arctic Wolf has confirmed that Qilin ransomware operators are actively exploiting a Palo Alto Networks GlobalProtect authentication bypass to breach corporate networks.
SharePoint CVE-2026-50522: Deserialization RCE Under Active Exploitation
Microsoft SharePoint Server contains a critical deserialization vulnerability (CVSS 9.8) allowing unauthenticated remote code execution over the network. This is the fifth SharePoint vulnerability exploited in a sustained campaign targeting on-premises deployments. watchTowr has observed active exploitation following the release of a public proof-of-concept, with attackers stealing IIS machine keys to maintain persistent access even after patching. Defused Cyber reports that captured exploit requests carry no authentication material, consistent with the unauthenticated attack profile. CISA's remediation deadline is July 25.
This is not a single CVE to patch and move on. The sustained SharePoint campaign (CVEs 32201, 45659, 56164, 58644, and now 50522) demands patching, machine key rotation, and credential reset on any exposed SharePoint server. Organisations that patched earlier SharePoint CVEs without rotating machine keys should assume persistence mechanisms may already be in place.
Check Point SmartConsole CVE-2026-16232: Firewall Management Plane Compromise
Check Point SmartConsole contains an improper authentication vulnerability (CVSS 9.3) that allows unauthenticated remote attackers to obtain an application login token and authenticate with full administrative privileges over firewall management. This affects Security Management and Multi-Domain Management running R81.10 through R82.10. Check Point has confirmed active exploitation affecting a limited number of customers whose management interfaces were exposed directly to the internet without IP restrictions. The vendor has released a jumbo hotfix alongside additional hardening fixes. CISA's remediation deadline is July 25.
Firewall management plane compromise is a worst-case scenario. An attacker with full SmartConsole privileges can modify security policies, disable logging, create backdoor access rules, and reconfigure VPN tunnels. The observed indicator of compromise is connections from specific IP addresses (151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250, 194.213.18.137) to management interfaces. Smart-1 Cloud customers are already protected. On-premises management must apply the jumbo hotfix immediately and restrict management access to trusted IP ranges.
Qilin Ransomware Deployed via Palo Alto GlobalProtect CVE-2026-0257
Arctic Wolf Labs has confirmed that Qilin ransomware operators are exploiting CVE-2026-0257 (CVSS 7.8), a GlobalProtect authentication bypass in PAN-OS, to gain unauthenticated VPN access and deploy ransomware. The flaw becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations. Multiple intrusions throughout June 2026 traced back to this single entry point. Post-exploitation activity includes LSASS credential dumping, full Active Directory database extraction via ntdsutil, lateral movement via PsExec, data exfiltration to MEGA cloud storage using Rclone, and encryption via a password-protected payload staged in C:\PerfLogs. Attackers also disabled Microsoft Defender real-time protection and wiped all Windows Event Log channels before ransomware deployment. Affected PAN-OS versions include 12.1, 11.2, 11.1, and 10.2 prior to patched builds.
So What / Action
Three urgent actions this week. First, patch SharePoint Server immediately and rotate IIS machine keys on any internet-facing instance. Patching without key rotation leaves the door open. Second, apply the Check Point jumbo hotfix to all Security Management and Multi-Domain Management servers, verify management interface access is restricted to trusted IPs, and check logs for connections from the listed IoC IPs. Third, for Palo Alto GlobalProtect, apply PAN-OS patches for CVE-2026-0257 across all internet-facing firewalls, terminate all active GlobalProtect sessions after patching, and if you suspect prior exploitation, rotate all domain credentials including the KRBTGT account. Monitor for execution from C:\PerfLogs and ensure Windows Event Logs are forwarded to a centralised SIEM to preserve evidence even if local logs are cleared. All three are in active exploitation with documented ransomware or persistence activity. This is not patch-and-forget week.

