The IT Guys 5 PM Tech News Recap for July 23, 2026

Jennifer presenting The IT Guys 5 PM technology news recap for July 23, 2026 in a realistic newsroom.

Today is Thursday, July 23, 2026. This is The IT Guys 5 PM technology news recap for home users and small businesses. The biggest practical theme today is trust: trusting email to keep flowing, trusting security appliances to stay patched, trusting AI tools without handing them the keys to the business, and trusting collaboration software to show the right people in the right meeting.

Here is what matters, what is good, what is bad, and what you should actually do with it.

1. Microsoft is still working on an Exchange Online mailbox quarantine problem

BleepingComputer reported today that Microsoft is working to fix an Exchange Online issue tracked as EX1436407. The problem began on July 19, 2026 and caused some customer mailboxes to be incorrectly quarantined. For affected users, that can mean trouble receiving email, trouble sending email, calendar access problems, and non-delivery reports for people trying to reach those mailboxes.

The useful detail is the likely cause: Microsoft tied the incident to a recent infrastructure change that created excessive memory use from unexpected indexing data. In plain English, this was not a normal “your password is wrong” or “your Outlook profile is broken” issue. It was a cloud-side service problem that could look like a local user problem if you only check the workstation.

Why this matters for small businesses

  • Bad news: Email outages are still business outages. If a mailbox is wrongly quarantined, invoices, approvals, customer replies, calendar changes, and support messages can all stall.
  • Good news: This is the kind of issue where a disciplined admin check can prevent wasted troubleshooting. Before rebuilding Outlook profiles or wiping phones, check the Microsoft 365 admin center, service health, message trace, quarantine status, and whether multiple users are seeing related symptoms.
  • Local IT takeaway: Keep at least one alternate communication path documented. A simple “if Microsoft 365 mail is down, use this phone/SMS/secondary mailbox/vendor portal” note can save a lot of confusion during a live incident.

If your business depends on Microsoft 365, this is also a reminder to review backup and continuity. Microsoft 365 is resilient, but cloud service resilience is not the same thing as a business continuity plan. If you need help checking Microsoft 365 health, mailbox access, or email continuity, start with The IT Guys and include what users are seeing, whether mail can be sent, and whether calendar access is affected.

2. CISA added actively exploited Check Point SmartConsole vulnerability CVE-2026-16232 to KEV

The security item with the shortest fuse today is CVE-2026-16232, a Check Point SmartConsole improper authentication vulnerability. CISA’s Known Exploited Vulnerabilities catalog lists it as added on July 22, 2026, with a due date of July 25, 2026 for federal civilian agencies. CISA describes the issue as a flaw that could allow an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges.

Rapid7’s July 23 analysis says Check Point published an advisory on July 22 covering multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. Rapid7 highlights CVE-2026-16232 as the urgent one because it is already being exploited in the wild. Remote exploitation requires network access to the Management Server IP address in environments that do not restrict Trusted Clients.

This is not a “patch it sometime next month” story. Security management systems and firewalls sit near the center of a network’s trust model. If an attacker gets administrative access there, they may be able to change policy, maintain persistence, hide traffic, or create paths deeper into the business.

What to do now

  • Check whether your environment uses affected Check Point Security Management or Multi-Domain Management versions.
  • Apply Check Point’s recommended Jumbo Hotfixes and mitigations from the vendor advisory.
  • Restrict trusted clients and management server access. Management interfaces should not be broadly reachable.
  • Review logs for unexpected SmartConsole authentication, administrative changes, new accounts, altered rules, and unusual source IPs.
  • If you use an MSP or firewall vendor, ask them directly whether this CVE applies and when the fix was installed.

For home users, this is less likely to apply unless you run business-grade Check Point gear. For small businesses, medical offices, accounting firms, shops with VPN access, and organizations using managed firewalls, this deserves immediate attention.

3. SharePoint remains in the exploited-vulnerability spotlight

The same CISA KEV pull also shows CVE-2026-50522, a Microsoft SharePoint deserialization vulnerability, added on July 22, 2026 with a July 25, 2026 due date. CISA’s catalog description says the flaw could allow an unauthorized attacker to execute code over a network.

The practical distinction matters: SharePoint Online is Microsoft’s cloud-hosted service, while SharePoint Server is self-hosted infrastructure that a business or vendor has to patch and monitor. Many small businesses do not run on-premises SharePoint anymore, but some still inherit it through older line-of-business systems, document portals, intranet projects, or vendor-managed environments.

  • Bad news: Internet-facing collaboration servers are high-value targets. If you still have on-premises SharePoint, patching discipline matters.
  • Good news: This is discoverable. An IT provider can inventory whether SharePoint Server exists, confirm version/build status, check exposure, and review logs.
  • Local IT takeaway: Do not assume “we use Microsoft 365” means you have no on-premises Microsoft servers. Ask for a current server inventory and external exposure check.

4. Google Workspace makes calendar delegation clearer

On the good-news side, Google Workspace announced that users can view supporting calendar delegates in a meeting guest list. Rapid Release domains start a gradual rollout on July 23, 2026, and Scheduled Release domains begin rollout on August 3, 2026. Google says the feature is available to all Google Workspace customers, Workspace Individual subscribers, and personal Google accounts.

This sounds small, but it helps offices where assistants, dispatchers, office managers, medical front desks, and administrative staff schedule on behalf of someone else. Seeing delegate context can reduce “who accepted this?” confusion and make meeting ownership clearer.

  • Good news: Better calendar transparency means fewer accidental no-shows and less detective work.
  • Watch item: Delegation permissions should still be reviewed. If someone no longer needs calendar access, remove it.
  • Local IT takeaway: Calendar delegation is a security and workflow setting. Audit it the same way you audit mailbox delegates, shared drives, and admin roles.

5. Google Cloud adds useful reliability and AI-adjacent admin features

Google Cloud’s July 23 release notes include several items that matter to technical teams and vendors who support small businesses. Apigee hybrid added runtime rollout strategy configuration, which helps teams control how runtime components are updated. Google Kubernetes Engine added observability improvements such as pressure stall information metrics and vertical pod autoscaler decision logging. Cloud Run service health for highly available multi-region failover is generally available, and Google Cloud NetApp Volumes remote Model Context Protocol server is generally available for managing storage resources from AI-enabled development tools.

Most small businesses will not touch these controls directly, but their software vendors might. Better rollout controls, autoscaling visibility, and failover features can reduce the kind of “the app is slow and nobody knows why” problems that eventually become support tickets for customers.

  • Good news: Cloud platforms are adding more operational visibility and safer rollout options.
  • Watch item: AI-connected admin tools that can manage infrastructure need strong access control, logging, and change approval. Convenience should not bypass change management.
  • Local IT takeaway: Ask vendors what their cloud recovery plan looks like: backups, failover, alerting, rollback, and who gets paged when something breaks.

6. Google ATLAS study: AI is broad, but not as automated as the hype suggests

Axios reported today on Google’s ATLAS study, short for Activity, Task, Landscape and Adoption Study. The study analyzed 14.65 million de-identified interactions across the Gemini app, Google’s AI Mode search experience, and the Gemini API over two weeks in April. According to the report, AI usage touched a wide range of jobs, but the average worker used it for a smaller portion of tasks, and less than 10% of Gemini interactions appeared geared toward automating non-routine cognitive work.

That is useful context for small businesses. AI is not just for programmers, marketers, or executives. People are using it for research, drafting, troubleshooting, image/video-assisted work, customer communication, forms, government processes, and practical everyday tasks. But the data also argues against magical thinking. Buying an AI subscription does not automatically redesign a business process.

  • Good news: AI can help ordinary work now, especially writing drafts, summarizing information, comparing options, and turning messy notes into usable plans.
  • Bad news: Shallow use can create shallow value. Without rules, training, and review, AI can also leak sensitive information or produce confident mistakes.
  • Local IT takeaway: Treat AI rollout like any other business system: define approved tools, data rules, review requirements, and workflows where it is allowed to help.

Today’s quick checklist

  • If your Microsoft 365 email acted strange this week, check service health before rebuilding devices.
  • If you use Check Point Security Management or Multi-Domain Management, treat CVE-2026-16232 as urgent.
  • If you still run SharePoint Server, confirm current patch status and external exposure.
  • If you use Google Workspace delegation, review who can manage calendars and mailboxes.
  • If your team uses AI, write down what data can and cannot be pasted into AI tools.

Bottom line

Today’s recap has a useful balance: cloud providers are improving admin visibility and collaboration features, AI is becoming a practical helper across more jobs, and security teams have urgent exploited vulnerabilities to close. For small businesses, the best move is not panic. It is inventory, patching, access review, and clear communication.

If your business needs help checking Microsoft 365, Google Workspace, firewall exposure, patch status, backups, or practical AI rules, contact The IT Guys. The goal is simple: fewer surprises, clearer systems, and technology that works when the business needs it.

Sources