Topic: sharepoint vulnerability

  • Microsoft SharePoint Spoofing Attacks Affect 1,300+ Servers

    Microsoft SharePoint Spoofing Attacks Affect 1,300+ Servers

    Over 1,300 internet-exposed Microsoft SharePoint servers remain vulnerable to an actively exploited spoofing flaw (CVE-2026-32201), despite a patch being released in April's security updates. The vulnerability, stemming from improper input validation, allows for network spoofing attacks that can ...

    Read More »
  • Urgent CISA Alert: Active Microsoft SharePoint Exploit

    Urgent CISA Alert: Active Microsoft SharePoint Exploit

    A critical, actively exploited security flaw (CVE-2026-20963) in Microsoft SharePoint has been added to CISA's Known Exploited Vulnerabilities catalog, requiring urgent patching. The vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected SharePoint servers wit...

    Read More »
  • New Microsoft SharePoint exploit used in active hacker attacks

    New Microsoft SharePoint exploit used in active hacker attacks

    CVE-2026-55040, a critical JWT authentication bypass in Microsoft SharePoint, is being actively exploited in the wild within a day of Rapid7 publishing a proof-of-concept exploit, allowing unauthenticated attackers to impersonate users or admins. Microsoft patched the flaw in its July 2026 Patch ...

    Read More »
  • Active SharePoint RCE flaw exploited to steal machine keys

    Active SharePoint RCE flaw exploited to steal machine keys

    Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys, allowing them to forge authentication tokens and maintain persistent access even after patches are applied. The flaw, a deserialization-of-untrusted-data issue, was patched in ...

    Read More »
  • Microsoft Patches Critical SharePoint RCE Flaw CVE-2026-45659

    Microsoft Patches Critical SharePoint RCE Flaw CVE-2026-45659

    Microsoft patched a critical SharePoint RCE vulnerability (CVE-2026-45659) affecting on-premises versions, including Server Subscription Edition, 2019, and 2016. The flaw allows authenticated attackers to execute arbitrary code with low complexity by exploiting deserialized untrusted data, though...

    Read More »
  • Microsoft Patches 622 Flaws, Including Two Actively Attacked Zero-Days

    Microsoft Patches 622 Flaws, Including Two Actively Attacked Zero-Days

    Microsoft's July 2026 Patch Tuesday is the largest on record, addressing 622 vulnerabilities, including two actively exploited zero-days in SharePoint Server and AD FS that require immediate patching. The most critical zero-day, CVE-2026-56164, allows unauthenticated remote privilege escalation i...

    Read More »
  • Microsoft Patch Tuesday Fixes Critical Security Bugs

    Microsoft Patch Tuesday Fixes Critical Security Bugs

    Microsoft's April 2026 Patch Tuesday addressed a record 165 vulnerabilities, including a critical, actively exploited SharePoint Server spoofing flaw (CVE-2026-32201) that could allow unauthorized data access or alteration. The massive update, the company's second-largest ever, is speculated to b...

    Read More »
  • Colt Data Breach: Warlock Ransomware Auctions Stolen Customer Files

    Colt Data Breach: Warlock Ransomware Auctions Stolen Customer Files

    Colt Technology Services experienced a data breach where customer documentation was stolen and is now being auctioned online by the Warlock ransomware gang. The stolen files include sensitive financial records, network architecture details, and extensive customer information, with the gang demand...

    Read More »