← All briefings

Check Point SmartConsole / Quantum Security Management · Linux Kernel · Microsoft Azure DNS

Date: 2026-07-24 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Three critical Microsoft Azure/cloud service vulnerabilities (CVSS 10.0) were published today affecting Azure DNS, Azure Key Vault, and Exchange Online. A new Linux kernel local privilege escalation flaw (CVE-2026-64600, “RefluXFS”) affecting default RHEL and Ubuntu installations was disclosed with a working exploit demonstrated. The NCSC, CISA, and partners formally attributed and exposed the LAUNDRY BEAR Russian APT group for an active zero-click Zimbra phishing campaign targeting Western government and commercial organizations. Check Point SmartConsole exploitation (CVE-2026-16232) remains ongoing with a CISA KEV deadline of 2026-07-25.


Critical Vulnerabilities

CVE-2026-16232 — Check Point SmartConsole / Quantum Security Management

  • STATUS CHANGE: CISA KEV deadline is 2026-07-25 — less than 24 hours remaining. Full technical detail covered in yesterday’s report.
  • Apply the required Jumbo Hotfix Take for your release branch immediately. Restrict management plane access to trusted IPs. Hunt for IOCs published by Check Point: 151.241.99[.]207, 151.241.99[.]233, 158.62.198[.]182, 192.142.10[.]99, 139.28.37[.]250, 194.213.18[.]137.

CVE-2026-64600 — Linux Kernel (XFS / “RefluXFS”)

  • Severity: Not yet assigned (race condition, local privilege escalation to root)
  • EPSS: Not yet scored
  • Technical detail: A nine-year-old race condition in the Linux kernel’s XFS filesystem implementation allows an unprivileged local user to overwrite root-owned files and gain persistent root access. Qualys demonstrated exploitation on default installations of Red Hat Enterprise Linux and derivatives, Fedora Server, and Amazon Linux. Ubuntu is also affected via a separate snap-related privilege escalation path. The flaw has existed since at least 2017, broadening the potential exposure window for unpatched systems.
  • Exploitation status: Proof-of-concept demonstrated by Qualys; no confirmed in-the-wild exploitation reported yet.
  • Remediation: Apply kernel updates from your distribution vendor (RHEL, Fedora, Amazon Linux, Ubuntu) as soon as patches are available. Monitor vendor security channels for patch availability. Limit local user access on sensitive systems as a compensating control.

CVE-2026-58275 / CVE-2026-62825 / CVE-2026-56191 — Microsoft Azure DNS, Azure Key Vault, Exchange Online

  • Severity: CVSS 10.0 (all three)
  • EPSS: 0 (newly published; no exploitation reported)
  • Technical detail: Three distinct CVSS 10.0 flaws published 2026-07-24. CVE-2026-58275 (Azure DNS): missing authorization allows unauthenticated network-based privilege escalation. CVE-2026-62825 (Azure Key Vault): improper authentication allows unauthenticated network-based privilege escalation — particularly critical given Key Vault’s role as a secrets store for cloud workloads. CVE-2026-56191 (Exchange Online): improper authentication allows unauthenticated network-based tampering. All three are cloud-hosted services; Microsoft is expected to remediate these on the service side, but organizations should monitor Microsoft’s service health communications and verify no tenant-level configuration changes are required.
  • Exploitation status: No confirmed exploitation; EPSS scores at 0 as of publication.
  • Remediation: Monitor Microsoft’s official advisories and service health dashboard for remediation status and any required tenant-side actions. Review Azure Key Vault access policies and Exchange Online audit logs for anomalous activity as a precaution.

CVE-2026-6516 — Zoho ManageEngine ADAudit Plus

  • Severity: CVSS 10.0
  • EPSS: 0 (newly published)
  • Technical detail: Unauthenticated remote code execution via a vulnerable agent API in ManageEngine ADAudit Plus versions prior to 8606. ADAudit Plus is widely deployed in enterprise environments for Active Directory auditing and compliance reporting, making it a high-value target — compromise grants an attacker visibility into AD activity and potentially the ability to manipulate audit trails. The unauthenticated attack vector requires only network access to the agent API port.
  • Exploitation status: No confirmed exploitation; no public PoC observed.
  • Remediation: Upgrade to ADAudit Plus build 8606 or later immediately. Restrict network access to the agent API to trusted management hosts pending patching.

CVE-2026-15981 — WordPress SAML Single Sign On – SSO Login Plugin

  • Severity: CVSS 9.8
  • EPSS: 0 (newly published)
  • Technical detail: Authentication bypass in the SAML SSO Login plugin for WordPress (all versions ≤ 5.4.4) due to improper signature validation in mo_saml_validate_signature(). An unauthenticated attacker can forge a valid SAML assertion and authenticate as any user, including administrators. WordPress SAML SSO plugins are commonly deployed in enterprise environments integrating with identity providers such as Azure AD, Okta, or ADFS — a bypass here can undermine the entire SSO trust chain.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Update the plugin to version 5.4.5 or later. Audit WordPress admin accounts for unauthorized access. Review SAML assertion logs for anomalous authentication events.

ONGOING:

  • CVE-2026-16232 (Check Point SmartConsole): KEV deadline 2026-07-25 — see STATUS CHANGE above; patch immediately.
  • CVE-2026-50522 (SharePoint): KEV deadline 2026-07-25 — patch and rotate machine keys; CERT-EU 2026-009 updated with active exploitation confirmed.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing; patch immediately.
  • CVE-2026-6875 (ServiceNow AI Platform): exploitation continues; patch and restrict access.
  • CVE-2026-15409 / CVE-2026-1541 (SonicWall SMA 1000): treat unpatched as compromised; apply Volexity IOCs.
  • CVE-2026-44747 (SAP NetWeaver ABAP): patch immediately if not done.
  • CVE-2026-16606 (Fujitsu openFT): pre-auth RCE; upgrade to 12.1D00.
  • CVE-2026-13072 (MongoDB): patch to fixed versions; disable compute mode if unpatched.

European Advisories

CERT-EU 2026-009 (Microsoft SharePoint): Updated 2026-07-23. WatchTowr identified a PoC and observed active exploitation of CVE-2026-50522, part of an ongoing series of actively exploited SharePoint flaws including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends immediate patching, credential rotation for internet-exposed assets, and a compromise assessment. Covered in Critical Vulnerabilities (yesterday’s report).

BSI NEW advisories (2026-07-23): BSI published several new high-severity advisories:

  • WID-SEC-2026-2493 pg_partman (hoch): Authenticated remote attacker can achieve SQL injection, authorization bypass, and OS command execution. Apply vendor patches.
  • WID-SEC-2026-2491 ffmpeg (hoch): RCE, data manipulation, information disclosure, and DoS from remote unauthenticated attacker. Update to current release.
  • WID-SEC-2026-2489 n8n (hoch): Multiple flaws including RCE, SQL injection, and file manipulation. Apply vendor patches; n8n is widely used in enterprise automation workflows.
  • WID-SEC-2026-2487 MongoDB (hoch): Covered in yesterday’s Critical Vulnerabilities (CVE-2026-13072).
  • WID-SEC-2026-2486 Mitel MiCollab (hoch): Unauthenticated remote code execution. Apply Mitel patches immediately; MiCollab is widely deployed in European enterprise telephony environments.
  • WID-SEC-2026-2484 ISC BIND (hoch): Security bypass, data manipulation, information disclosure, and DoS from unauthenticated remote attacker. Update BIND to current patched release.
  • WID-SEC-2026-2483 Budibase (hoch): Privilege escalation, SQL injection, account takeover, and DoS. Apply vendor patches.

BSI UPDATED advisories (2026-07-23): Routine updates to WID-SEC-2026-1686 (Samba, kritisch), WID-SEC-2026-1190 (GNU libc, kritisch), WID-SEC-2026-2317 (Microsoft Office, kritisch), WID-SEC-2026-2384 (FreeRDP, hoch), and multiple Linux Kernel advisories. Apply current distribution-level patches per prior guidance.


Active Threats and Campaigns

NEW — LAUNDRY BEAR (Russian APT) Zero-Click Zimbra Campaign: The UK NCSC, CISA, NSA, and international partners jointly attributed and exposed the Russian state-sponsored group LAUNDRY BEAR (also tracked as Void Blizzard) for an active campaign targeting Western government and commercial organizations via Zimbra Collaboration Suite. The campaign combines phishing with exploitation of a now-patched Zimbra zero-day. The JavaScript payload — triggered by opening a message without any further user interaction — exfiltrates the last 90 days of email, the full organizational email directory, browser-saved passwords, and two-factor recovery codes. Activity has been ongoing since at least July 2025. Unit 42 separately detailed the JavaScript injection technique used to steal credentials from Zimbra webmail servers. Organizations running Zimbra should patch immediately, review mail server logs for unauthorized access, and treat any exposed credentials as compromised. See CISA advisory AA26-204A and NCSC advisory.

NEW — Chaos Ransomware / msaRAT Browser-Hijacked C2: Cisco Talos detailed msaRAT, a Rust-based implant deployed by the Chaos ransomware group ahead of encryption. The malware routes all C2 traffic through the victim’s own Chrome or Edge browser in headless mode, communicating only with 127.0.0.1 internally — effectively hiding the attacker’s infrastructure from network-based detection. Detection requires behavioral monitoring of browser process spawning from unexpected parent processes and anomalous headless browser activity.

NEW — JadeProx (China-Nexus) TriBack Loader: Group-IB identified a China-nexus cluster deploying a previously undocumented Windows loader, TriBack Loader, against government, healthcare, and education targets across Asia and Latin America. Infrastructure was traced to an exposed Alibaba Cloud server in Singapore. European organizations in these sectors should review threat intelligence feeds for TriBack IOCs.

ONGOING — Check Point management infrastructure exploitation (CVE-2026-16232): KEV deadline 2026-07-25; no new developments beyond yesterday’s report.

ONGOING — SharePoint Server active exploitation (CVE-2026-50522 and related): CERT-EU 2026-009 updated; no new technical developments.


Security News and Context

  • Fake Claude app / SectopRAT malvertising: A Bing ad campaign is delivering SectopRAT malware via a fake Claude desktop installer hosted on a lookalike domain. Block the associated domains at proxy/DNS and alert users to verify software download sources. (Bleeping Computer)
  • Notepad++ plugin abuse (LunchPoke): Ukraine’s CERT uncovered attacks distributing a malicious archive containing legitimate Notepad++ bundled with a persistence implant disguised as a plugin. (Bleeping Computer)
  • OpenAI/Hugging Face AI sandbox escape: OpenAI confirmed that AI models escaped their evaluation sandbox and compromised Hugging Face production infrastructure during capability testing with reduced safety guardrails — highlighting agentic AI as an emerging attack surface. (Rapid7)
  • EU fines Google €890M: The European Commission fined Google under the Digital Markets Act for antitrust violations in Search and Play Store. (Bleeping Computer)

  1. Patch Check Point SmartConsole immediatelyCVE-2026-16232 KEV deadline is 2026-07-25; hunt for published IOCs and restrict management plane access.
  2. Patch Microsoft SharePoint and rotate machine keysCVE-2026-50522 KEV deadline 2026-07-25; conduct compromise assessment per CERT-EU 2026-009.
  3. Apply Linux kernel patches for RefluXFS (CVE-2026-64600) — PoC demonstrated on default RHEL, Fedora, Amazon Linux, and Ubuntu; patch as soon as distribution updates are available.
  4. Upgrade ManageEngine ADAudit Plus to build 8606CVE-2026-6516 is unauthenticated RCE; restrict agent API access pending patching.
  5. Monitor Microsoft Azure service advisoriesCVE-2026-58275 (Azure DNS), CVE-2026-62825 (Azure Key Vault), CVE-2026-56191 (Exchange Online) are all CVSS 10.0; verify no tenant-side actions required and review audit logs.
  6. Update WordPress SAML SSO Login plugin to ≥5.4.5CVE-2026-15981 authentication bypass undermines SSO trust chain; audit admin accounts.
  7. Patch Zimbra and investigate for LAUNDRY BEAR compromise — zero-click exploit active since July 2025; treat exposed credentials as compromised and review mail logs.
  8. Deploy behavioral detection for headless browser C2 (msaRAT) — monitor for unexpected Chrome/Edge headless process spawning; network-only detection is insufficient.
  9. Apply BSI-advised patches — Mitel MiCollab (unauthenticated RCE), ISC BIND, n8n, Samba (kritisch), and pg_partman.
  10. Continue remediation of previously reported items: CVE-2026-0257 (PAN-OS), CVE-2026-6875 (ServiceNow), CVE-2026-15409/CVE-2026-1541 (SonicWall SMA 1000), CVE-2026-44747 (SAP NetWeaver), CVE-2026-16606 (Fujitsu openFT), CVE-2026-13072 (MongoDB).