Tag

#Microsoft SharePoint

10 stories taggedMicrosoft SharePoint.

Illustration for the story: Kiteworks Told Customers to Go Dark for Nine Hours After a Federal Warning
Vulnerabilities

Kiteworks Told Customers to Go Dark for Nine Hours After a Federal Warning

Fewer than 50 organisations use the affected feature. No breach has been confirmed. But the feds thought the risk serious enough to pick up the phone.

3 min read
Illustration: a dimly lit server room with rows of dark network racks and cool blue status lights
Vulnerabilities

Microsoft Called This SharePoint Bug a Spoofing Issue. It Runs Code.

A vulnerability first rated medium turned out to let logged-in users execute code on the server. The researcher who found it just published the details.

3 min read
A network diagram displayed on a security operations center screen showing attack chain progression through server nodes, with two highlighted vulnerabilities c
Vulnerabilities

Hackers Are Now Chaining Two SharePoint Bugs to Take Over Servers

A public proof-of-concept turned into live attacks within a day, and researchers are watching the full two-step break-in play out in honeypots.

3 min read
Multiple windows showing security patch notifications and system update dialogs stacked across a desktop environment, with warning badges highlighted in red and
Vulnerabilities

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products

The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

4 min read
A SharePoint server interface with authentication mechanism broken, showing unauthorized access pathways and AI chain-attack visualization flowing through multi
Vulnerabilities

SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.

Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

3 min read
Illustration: a dimly lit corporate server room, rows of rack-mounted servers glowing with amber and blue status lights
Vulnerabilities

Third SharePoint Flaw From July Patch Batch Is Now Being Attacked

CVE-2026-50522 lets unauthenticated attackers run code on SharePoint servers. A public proof-of-concept dropped, and the exploitation followed.

4 min read
A government IT department frantically updating systems at night, multiple technicians at workstations with security patches being deployed across networks, urg
Vulnerabilities

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago

CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

3 min read
Illustration: a dimly lit server room with rack-mounted network security appliances, blinking amber status lights
Vulnerabilities

CISA Flags Three Actively Exploited Bugs in Fortinet and SharePoint

Two Fortinet FortiSandbox command-injection flaws and a Microsoft SharePoint deserialization bug are being used in real attacks, the US cyber agency warns.

3 min read
Illustration: a dimly lit government server room, rows of racks with faint blue and amber status LEDs
Policy & Regulation

CISA orders federal agencies to patch SharePoint flaw by Saturday as attacks begin

A newly exploited Microsoft SharePoint bug lands in CISA's Known Exploited Vulnerabilities Catalog, triggering a three-day patching clock under Binding Operational Directive 26-04.

3 min read
Illustration for the story: CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint
Vulnerabilities

CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint

A vulnerability in SharePoint, Microsoft's widely used workplace collaboration platform, lets criminals run malicious code on company servers. Patches have been available since late May. Many organisations haven't applied them.

3 min read
© 2026 Threat Vectr