Tag

Sharepoint

All articles tagged with #sharepoint

Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns
security14 days ago

Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns

CISA confirms ransomware groups are actively exploiting CVE-2026-45659, a SharePoint deserialization/RCE flaw that allows low-privilege attackers to execute arbitrary code on unpatched servers, with activity dating back to early July. Federal agencies were ordered to patch within three days and to monitor for signs of exploitation, applying the latest fixes and enabling AMSI integration and Defender detections. Shadowserver tracks thousands of internet-exposed SharePoint servers, including hundreds unpatched; CISA notes 14 exposed SharePoint vulns have been exploited since 2021, eight in ransomware campaigns. A second high-severity flaw, CVE-2026-33825 (BlueHammer), was also linked to attacks last month, though Microsoft has not confirmed wild exploitation.

SharePoint deserialization flaw used to steal machine keys and sustain access after patching
security1 month ago

SharePoint deserialization flaw used to steal machine keys and sustain access after patching

Security researchers warn that the critical SharePoint deserialization flaw CVE-2026-50522 is being exploited to steal machine keys, enabling attackers to forge tokens and linger on-premises deployments even after patches; PoC exploits circulated online, prompting defenders to apply July updates and rotate credentials to limit exposure.

Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522
security1 month ago

Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522

Microsoft patched CVE-2026-50522, a critical deserialization-based RCE in SharePoint Server, but a public PoC and threat intel indicate active exploitation of on‑prem deployments. The flaw allows remote code execution over the network, potentially by an attacker authenticated as a Site Owner, enabling arbitrary code execution and theft of IIS machine keys for persistence. Defenders should rotate credentials and deploy patches; CISA warns that multiple SharePoint vulnerabilities are being exploited across supported on‑premises versions.

CISA adds SharePoint zero-day to KEV, agencies told to patch by July 19
security1 month ago

CISA adds SharePoint zero-day to KEV, agencies told to patch by July 19

CISA added CVE-2026-58644, a critical deserialization RCE in Microsoft SharePoint Server, to the Known Exploited Vulnerabilities catalog, with FCEB agencies required to patch by July 19, 2026. Microsoft said the flaw was exploited in the wild before fixes were released (patches issued July 14, 2026). The warning comes as CISA notes ongoing exploitation of multiple on-premises SharePoint vulnerabilities and urges hardening steps: apply patches, enable AMSI, scan for intrusion artifacts, tailor logging, and avoid exposing SharePoint servers to the internet.

New LegacyHive PoC Sparks Windows Privilege Escalation Talk After Patch Tuesday
technology1 month ago

New LegacyHive PoC Sparks Windows Privilege Escalation Talk After Patch Tuesday

Security researcher Chaotic Eclipse released LegacyHive, a PoC for a Windows User Profile Service privilege-escalation vulnerability. The PoC reportedly requires an extra standard credential and a third username (potentially an admin) and, if successful, mounts the target user hive in the current user classes root; the exploit is claimed to work on all supported Windows editions, including the July 2026 Patch Tuesday versions. The disclosure comes amid a disputed back-and-forth with Microsoft, ongoing Defender flaws, and a wave of Patch Tuesday fixes, notably for SharePoint Server, with CISA listing several flaws as actively exploited. The piece highlights growing turbulence around Patch Tuesday disclosures in 2026.

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert
technology1 month ago

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert

CISA warns that three on‑premises SharePoint Server flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) are being actively exploited to bypass authentication and run remote code, with attackers targeting unpatched systems. Microsoft also patched CVE-2026-55040 and CVE-2026-58644. Shadowserver reports thousands of exposed SharePoint servers, prompting urgent patching, hardened logging, AMSI/Defender integration, and limiting internet exposure. Federal agencies have a July 17 deadline under BOD 26-04 to patch CVE-2026-56164. Since 2021, CISA has flagged 11 exploited Microsoft SharePoint vulnerabilities (7 linked to ransomware).

security1 month ago

CISA Warns of Active SharePoint Exploits, Urges Immediate Hardening

CISA warns of active exploitation of three on-premises SharePoint vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) that enable remote code execution and post-exploitation activity such as stealing IIS machine keys; two additional CVEs (CVE-2026-55040 and CVE-2026-58644) are also identified as potential risks if not patched. To mitigate, organizations should apply the latest Microsoft patches, verify installation completion, and shorten patching cycles where possible; ensure AMSI integration is enabled for all SharePoint web apps and follow Microsoft guidance for AMSI configuration. Use the provided AMSI and MDAV detections as part of incident response and hardening: hunt for intrusion artifacts before rotating IIS keys, implement enhanced logging and telemetry to detect anomalies, and limit internet exposure by placing SharePoint behind a Layer 7 proxy and restricting Central Administration access. Review Microsoft’s security guidance and report incidents to CISA as needed. These CVEs have been added to the Known Exploited Vulnerabilities (KEV) catalog.

Unpatched SharePoint spoofing flaw leaves 1,300+ servers at risk
technology4 months ago

Unpatched SharePoint spoofing flaw leaves 1,300+ servers at risk

More than 1,300 publicly reachable Microsoft SharePoint servers remain unpatched for CVE-2026-32201, a spoofing vulnerability that was exploited as a zero-day and can let attackers view and alter sensitive data without user interaction. The bug affects SharePoint Server 2016, 2019, and Subscription Edition; Microsoft issued patches in the April 2026 Patch Tuesday, but Shadowserver reports fewer than 200 systems updated so far. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered FCEB agencies to patch within two weeks, while Microsoft has not tied attacks to a specific actor. The vulnerability impacts confidentiality and integrity, not availability.

Microsoft Rolls Out Record Patch Tuesday: 169 Fixes Including SharePoint Zero-Day Exploited in the Wild
cybersecurity4 months ago

Microsoft Rolls Out Record Patch Tuesday: 169 Fixes Including SharePoint Zero-Day Exploited in the Wild

Microsoft released a record Patch Tuesday with 169 fixes across its products, highlighted by a SharePoint Server zero-day (CVE-2026-32201) that is actively exploited in the wild. The bundle also patches a Defender privilege-escalation flaw (CVE-2026-33825) tied to BlueHammer and a high-risk IKEv2 remote-code-execution issue (CVE-2026-33824) rated 9.8, along with extensive Edge updates and other critical/important vulnerabilities. Some of the flaws are listed in the CISA KEV catalog, triggering remediation deadlines for government agencies (by April 28, 2026).

Microsoft's August 2025 Patch Tuesday Addresses 111 Flaws and Critical Vulnerabilities
technology1 year ago

Microsoft's August 2025 Patch Tuesday Addresses 111 Flaws and Critical Vulnerabilities

Microsoft's August Patch Tuesday addresses 111 issues, including 12 critical vulnerabilities with remote code execution risks, notably in Windows, SharePoint, and Office. Adobe also released patches for 68 CVEs across its products. Other tech giants like SAP, Intel, and Google issued updates fixing multiple vulnerabilities, emphasizing ongoing cybersecurity efforts. Despite no active exploits reported, the severity of these flaws warrants prompt patching to prevent potential attacks.

Weekly Cybersecurity Recap: SharePoint Breach, Threat Actor Tools, and Global Attacks
cybersecurity1 year ago

Weekly Cybersecurity Recap: SharePoint Breach, Threat Actor Tools, and Global Attacks

This weekly cybersecurity recap highlights ongoing threats including Chinese-backed SharePoint zero-days, North Korean IT worker schemes, malware campaigns targeting cloud and crypto users, and law enforcement disruptions of cybercriminal groups, emphasizing the evolving landscape of trust-based attacks and the importance of proactive defense measures.

Microsoft Investigates SharePoint Breach and Ransomware Threats
technology1 year ago

Microsoft Investigates SharePoint Breach and Ransomware Threats

Microsoft is investigating whether a leak from its early alert system for cybersecurity partners, specifically the Microsoft Active Protections Program (MAPP), allowed Chinese hackers to exploit vulnerabilities in SharePoint before they were patched. The breach has affected over 400 entities worldwide, with suspected involvement of Chinese state-sponsored groups. Past incidents suggest potential leaks from the MAPP program, raising concerns about security and transparency, especially given Chinese laws requiring rapid vulnerability reporting and the involvement of Chinese companies in government-linked vulnerability programs.

Microsoft SharePoint Vulnerabilities Exploited in Widespread Ransomware Attacks
security1 year ago

Microsoft SharePoint Vulnerabilities Exploited in Widespread Ransomware Attacks

Microsoft reports that the threat group Storm-2603, suspected to be China-based, is exploiting SharePoint vulnerabilities (CVE-2025-49706 and CVE-2025-49704) to deploy Warlock ransomware, using web shells, credential harvesting, and lateral movement techniques. Users are advised to update SharePoint, apply security patches, and implement security best practices to mitigate the threat.