The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active…
Microsoft SharePoint Weak Authentication Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based…
Threat actors have begun exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS 9.1), following the public release of a proof-of-concept (PoC)…
Security researchers at Rapid7 have disclosed an AI-assisted exploit chain targeting Microsoft SharePoint Server that allows unauthenticated attackers to achieve remote code…
SharePoint Server 2019 is affected by both CVE-2026-55040 and CVE-2026-63520. The July update (KB5002883) breaks the chain, but the product reached end…
SharePoint Server 2016 is affected by both CVE-2026-55040 and CVE-2026-63520. The July update (KB5002891) breaks the chain, but the product reached end…
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit called LegacyHive, targeting a Windows User Profile Service (ProfSvc) arbitrary…