#Microsoft SharePoint
10 stories taggedMicrosoft SharePoint.

Kiteworks Told Customers to Go Dark for Nine Hours After a Federal Warning
Fewer than 50 organisations use the affected feature. No breach has been confirmed. But the feds thought the risk serious enough to pick up the phone.

Microsoft Called This SharePoint Bug a Spoofing Issue. It Runs Code.
A vulnerability first rated medium turned out to let logged-in users execute code on the server. The researcher who found it just published the details.

Hackers Are Now Chaining Two SharePoint Bugs to Take Over Servers
A public proof-of-concept turned into live attacks within a day, and researchers are watching the full two-step break-in play out in honeypots.

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products
The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.
Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

Third SharePoint Flaw From July Patch Batch Is Now Being Attacked
CVE-2026-50522 lets unauthenticated attackers run code on SharePoint servers. A public proof-of-concept dropped, and the exploitation followed.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

CISA Flags Three Actively Exploited Bugs in Fortinet and SharePoint
Two Fortinet FortiSandbox command-injection flaws and a Microsoft SharePoint deserialization bug are being used in real attacks, the US cyber agency warns.

CISA orders federal agencies to patch SharePoint flaw by Saturday as attacks begin
A newly exploited Microsoft SharePoint bug lands in CISA's Known Exploited Vulnerabilities Catalog, triggering a three-day patching clock under Binding Operational Directive 26-04.

CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint
A vulnerability in SharePoint, Microsoft's widely used workplace collaboration platform, lets criminals run malicious code on company servers. Patches have been available since late May. Many organisations haven't applied them.