Threat actors have begun exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS 9.1), following the public release of a proof-of-concept (PoC)…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
August 2026August 2026 Patch TuesdayMicrosoftPatch Tuesday
A critical remote code execution vulnerability in Microsoft SharePoint Server, CVE-2026-50522 (CVSS 9.8), is being actively exploited in the wild following the…
active exploitationCISACVE-2026-32201CVE-2026-45659
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Microsoft SharePoint Server, tracked as…
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit called LegacyHive, targeting a Windows User Profile Service (ProfSvc) arbitrary…
CVE-2025-9491 is a now-patched Windows shortcut vulnerability (ZDI-CAN-25373) that allows remote code execution. Addressed by Microsoft in November 2025 Patch Tuesday, it…
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass exploit named GreatXML, discovered accidentally while researching…