Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit called LegacyHive, targeting a Windows User Profile Service (ProfSvc) arbitrary…
CVE-2026-55040 is a critical SharePoint Server security feature bypass vulnerability with a CVSS score of 9.1. It allows remote unauthenticated attackers to…
authentication bypassCVE-2026-55040JWT Token ValidationSharePoint Server
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04…
SharePoint Server is a web-based collaboration platform by Microsoft. Multiple critical vulnerabilities (CVE-2026-56164, CVE-2026-32201, CVE-2026-45659, CVE-2026-55040) were patched in July 2026, with…
active exploitationcollaborationSharePoint Servervulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity remote code execution vulnerability, CVE-2026-45659 (CVSS 8.8), affecting Microsoft SharePoint…
active exploitationCISA KEVCloudflareCVE-2025-11371
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing…