← All stories
● Covered by 5 sources · 42 reportsHigh impact18 negative11 neutral

CISA Alerts on Active Exploitation of Multiple Microsoft SharePoint Vulnerabilities

🔄 Updated 5d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CISA added four SharePoint vulnerabilities to its KEV catalog.
  • CVE-2026-45659, CVE-2026-58644, and CVE-2026-50522 allow remote code execution.
  • CVE-2026-56164 is a privilege escalation flaw.
  • Exploitation often requires minimal privileges or no authentication.
  • Federal agencies must patch these flaws by CISA-mandated deadlines.
  • CVE-2026-45659 has a CVSS score of 8.8.
  • CVE-2026-45659 was addressed by Microsoft in May 2026.
  • CVE-2026-45659 impacts SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
  • CVE-2026-45659 is a deserialization of untrusted data vulnerability.
  • CVE-2026-45659 requires Site Member permissions for exploitation.
  • CISA mandated federal agencies patch CVE-2026-45659 by July 4, 2026.
  • Microsoft patched a record 622 vulnerabilities.
  • CVE-2026-56164 affects on-premises SharePoint Server.
  • CVE-2026-56164 was credited to Mandiant's incident responders and Google's FLARE team.
  • CISA warned of three actively exploited SharePoint vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164.
  • CVE-2026-32201 is a spoofing issue patched in April.
  • CVE-2026-55040 is a critical security bypass weakness.
  • CVE-2026-58644 has a CVSS score of 9.8.
  • CVE-2026-58644 allows an attacker authenticated as a Site Owner to execute code.
  • CISA mandated federal agencies patch CVE-2026-58644 by July 19, 2026.
  • CVE-2026-50522 has a CVSS score of 9.8.
  • CVE-2026-50522 was discovered by DEVCORE researcher "splitline".
  • CVE-2026-50522 allows an attacker authenticated as a Site Owner to execute code.
  • CVE-2026-50522 is being exploited to steal machine keys.
  • Defused observed exploitation attempts targeting CVE-2026-50522 on July 17.
  • Ransomware gangs exploit CVE-2025-60710.
  • CVE-2025-60710 is a Windows Task Host privilege escalation vulnerability.
  • CVE-2025-60710 allows attackers to gain SYSTEM privileges.
  • CVE-2025-60710 affects Windows 11 and Windows Server 2025.
  • CVE-2025-60710 was patched by Microsoft in November 2025.
  • CVE-2025-60710 stems from a link following weakness.
  • CISA added CVE-2025-60710 to its KEV catalog on April 13.
  • Federal agencies had two weeks to patch CVE-2025-60710.
  • CISA warned of CVE-2026-33824, a critical RCE flaw in Windows IKE Service Extensions.
  • CVE-2026-33824 impacts Windows 10, Windows 11, and Windows Server releases.
  • CVE-2026-33824 allows unauthenticated attackers to execute code via UDP ports 500 or 4500.
  • Microsoft addressed CVE-2026-33824 during the April 2026 Patch Tuesday.
  • CVE-2026-33824 is a double free vulnerability.
  • CVE-2026-33824 has a CVSS score of 9.8.
  • Palo Alto Networks flagged CVE-2026-33824 as exploited by a Chinese-speaking threat actor.
  • CVE-2026-55040 was fixed on Microsoft's July 2026 Patch Tuesday.
  • Threat actors started targeting CVE-2026-55040 after a PoC exploit was published.
  • CISA added CVE-2026-59310 to its KEV catalog.
  • CVE-2026-65400 is an improper authentication vulnerability impacting Apple macOS.
  • CVE-2026-65400 allows an attacker to authenticate to Screen Sharing without valid credentials.
  • CVE-2026-65400 has a CVSS score of 9.8.
  • CVE-2026-59310 is a path traversal vulnerability in Broadcom VMware vCenter.
  • CVE-2026-59310 allows a threat actor with network access to vCenter to execute arbitrary code.
  • CVE-2026-59310 has a CVSS score of 9.8.
  • Microsoft patched CVE-2026-69836 in its Entra ID service.
  • CVE-2026-69836 has a CVSS score of 10.0.
  • CVE-2026-69836 is a deserialization of untrusted data vulnerability.
  • Microsoft credited Robert Fitzaptrick for discovering CVE-2026-69836.
  • Microsoft released 22 new security updates.
  • CVE-2026-69502 is an EoP bug in Azure SQL Database.
  • CVE-2026-69502 has a CVSS score of 10/10.
  • CVE-2026-69555 is an EoP bug in Azure Arc.
  • CVE-2026-69555 has a CVSS score of 10/10.
  • CVE-2026-65816 is an EoP bug in Azure Arc.
  • CVE-2026-65816 has a CVSS score of 10/10.
  • CVE-2026-65801 is an EoP bug in Exchange Online.
  • CVE-2026-65801 has a CVSS score of 10/10.
  • CVE-2026-65770 is an RCE flaw in Azure Managed Instance for Apache Cassandra.
  • CVE-2026-65770 has a CVSS score of 10/10.
  • CVE-2026-68782 is an EoP issue in Azure SQL Database.
  • CVE-2026-63509 is an EoP issue in Microsoft Fabric.
  • CVE-2026-69851 is an EoP issue in Entra ID.
  • CVE-2026-68789 is an EoP issue in Azure SQL Database.
  • CVE-2026-69400 is an EoP issue in Azure Logic Apps.
  • CVE-2026-62834 is an EoP issue in Azure Data Factor.
  • CVE-2026-66309 is an EoP issue in Azure SQL Database.
  • CVE-2026-69836 affects Entra ID, formerly Azure Active Directory.
  • CVE-2026-69836 allows unprivileged attackers to achieve code execution.
  • Microsoft fully mitigated CVE-2026-69836; no user action is required.
  • Threat actors are targeting a chain of CVE-2026-55040 and CVE-2026-63520.
  • CVE-2026-63520 is a vulnerability in SharePoint's Business Connectivity Services (BCS).
  • CVE-2026-63520 allows unauthenticated attackers to execute arbitrary code.
  • Stephen Fewer released a PoC for CVE-2026-55040 on August 11.
  • Jonathan Peterson released a PoC for CVE-2026-63520 on August 24.
  • Defused reported weaponization of CVE-2026-55040 PoC one day after its release.
  • 22,000 Microsoft Exchange servers are vulnerable to CVE-2026-62911.
  • CVE-2026-62911 is an authentication bypass vulnerability.
  • CVE-2026-62911 allows attackers to hijack user mailboxes.
  • CVE-2026-62911 affects Exchange Server 2016, 2019, and Subscription Edition.
  • CVE-2026-62911 was reported by DEVCORE Research Team's Orange Tsai.
  • CVE-2026-62911 requires basic privileges and user interaction for exploitation.
  • Microsoft patched CVE-2026-62911 during the August 2026 Patch Tuesday.
  • NCSC-NL reported exploit code for CVE-2026-62911 is available online.
  • Microsoft patched 974 vulnerabilities.
  • CVE-2026-85880 is a heap buffer overflow in Windows ALPC.
  • CVE-2026-85880 allows a local attacker to gain System privileges.
  • CVE-2026-85880 requires no user interaction.
  • CVE-2026-85880 is the second ALPC zero-day in nearly four years.
  • CVE-2026-81963 is an improper link resolution defect in Windows Update Stack.
  • CVE-2026-81963 allows local attackers to elevate privileges to System.
  • CVE-2026-81963 is the first Update Stack security weakness.
  • Microsoft's latest Patch Tuesday addressed 973 vulnerabilities.
  • CISA mandated federal agencies patch CVE-2026-81963 and CVE-2026-85880 by September 22.
  • CVE-2026-81963 relates to a component used to install Windows updates.
  • CVE-2026-85880 affects a messaging system in Windows.
  • CVE-2026-65660 is a SharePoint Server vulnerability.
  • CVE-2026-65660 was initially classified as a spoofing flaw with a CVSS score of 6.5.
  • CVE-2026-65660 was re-evaluated as an authenticated remote code execution vulnerability.
  • Dinh Ho Anh Khoa re-evaluated CVE-2026-65660.
  • CVE-2026-65660 affects SharePoint Server 2016, 2019, and Subscription Edition.
  • Patches for CVE-2026-65660 have been available since August 11.
  • The National Vulnerability Database scores CVE-2026-65660 at 8.8.
  • Microsoft's advisory for CVE-2026-65660 describes it as allowing an authorized attacker to perform spoofing.
  • Microsoft's CVE record for CVE-2026-65660 was updated on September 11.
  • Both Microsoft records for CVE-2026-65660 assign CWE-94, a code-injection weakness.
  • Khoa demonstrated the ToolShell exploit chain at Pwn2Own Berlin in May 2025.
  • CISA warned of active exploitation of WSO2, Adobe Commerce, and Mikrotik RouterOS vulnerabilities.
  • CVE-2026-5430 is a critical authentication bypass in WSO2 products.
  • CVE-2026-71362 is a critical flaw in Adobe Commerce.
  • CVE-2026-67279 is a medium-severity pre-authentication SSH bypass in Mikrotik RouterOS.
  • Federal agencies must patch critical KEV issues by September 27.
  • CVE-2026-5430 impacts WSO2 API Manager versions 4.1.0-4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
  • WSO2 issued an advisory for CVE-2026-5430 on May 3.
  • CVE-2026-65660 is a code injection vulnerability.
  • CVE-2026-67279 has a CVSS score of 6.9.
  • CVE-2026-67279 is an improper enforcement of behavioral workflow vulnerability.
  • CVE-2026-67279 allows an unauthenticated client to open a session channel and send an exec request.
  • Microsoft had reliable evidence of observed attacks against CVE-2026-65660 as of September 25, 2026.
  • CVE-2026-65660 is being exploited in attacks.
  • CVE-2026-65660 allows an authenticated attacker with low-level access to execute arbitrary code without user interaction.
  • CISA added CVE-2026-65660 to its KEV catalog on September 25.
  • CISA mandated federal agencies patch CVE-2026-65660 by September 28.
  • Previdian reported exploitation attempts for CVE-2026-65660 on September 24.
  • Previdian observed attempts to create a webshell backdoor for CVE-2026-65660 on September 25.
  • Viettel Security researchers reported CVE-2026-65660 to Microsoft.

Overview of Exploited Vulnerabilities

CISA has issued a warning about multiple actively exploited vulnerabilities in Microsoft SharePoint Server. These include CVE-2026-45659, CVE-2026-50522, and CVE-2026-58644, all involving the deserialization of untrusted data. Exploitation allows attackers to run arbitrary code remotely, posing significant security risks to affected systems.

Details of Key Vulnerabilities

CVE-2026-45659 allows an authenticated attacker with site member permissions to execute arbitrary code on impacted SharePoint servers. Initially assessed as 'Exploitation Less Likely' by Microsoft, it was marked by CISA due to increased exploitation.

In addition, CVE-2026-50522, with a CVSS score of 9.8, emerged following the release of proof-of-concept exploit code targeting SharePoint's deserialization flaw, leading to unauthorized access and potential data compromise.

Microsoft's Security Updates

Microsoft issued patches in its July 2026 security updates to address these vulnerabilities. These updates aim to reduce exploitation risks by correcting the underlying flaws across multiple SharePoint versions, including Subscription Edition and Server 2019.

Urgent Patch Mandates

CISA has mandated federal agencies patch these vulnerabilities under its Known Exploited Vulnerabilities (KEV) guidelines by specific deadlines. Prompt patching is crucial to mitigate potential damage from these security breaches.

Impact on Organizations

Organizations using Microsoft SharePoint are advised to implement the provided patches immediately. Failure to do so may result in unauthorized access and persistent threats, notably from attackers leveraging these exploits to breach critical systems.

Updates

🕒 2026-09-27 · new reporting from SecurityWeek
  • CVE-2026-65660 is being exploited in attacks.
  • CVE-2026-65660 allows an authenticated attacker with low-level access to execute arbitrary code without user interaction.
  • CISA added CVE-2026-65660 to its KEV catalog on September 25.
  • CISA mandated federal agencies patch CVE-2026-65660 by September 28.
  • Previdian reported exploitation attempts for CVE-2026-65660 on September 24.
  • Previdian observed attempts to create a webshell backdoor for CVE-2026-65660 on September 25.
  • Viettel Security researchers reported CVE-2026-65660 to Microsoft.
🕒 2026-09-26 · new reporting from The Hacker News
  • CVE-2026-65660 is a code injection vulnerability.
  • CVE-2026-67279 has a CVSS score of 6.9.
  • CVE-2026-67279 is an improper enforcement of behavioral workflow vulnerability.
  • CVE-2026-67279 allows an unauthenticated client to open a session channel and send an exec request.
  • Microsoft had reliable evidence of observed attacks against CVE-2026-65660 as of September 25, 2026.
🕒 2026-09-25 · new reporting from BleepingComputer
  • CISA warned of active exploitation of WSO2, Adobe Commerce, and Mikrotik RouterOS vulnerabilities.
  • CVE-2026-5430 is a critical authentication bypass in WSO2 products.
  • CVE-2026-71362 is a critical flaw in Adobe Commerce.
  • CVE-2026-67279 is a medium-severity pre-authentication SSH bypass in Mikrotik RouterOS.
  • Federal agencies must patch critical KEV issues by September 27.
  • CVE-2026-5430 impacts WSO2 API Manager versions 4.1.0-4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
  • WSO2 issued an advisory for CVE-2026-5430 on May 3.
🕒 2026-09-22 · new reporting from The Hacker News
  • CVE-2026-65660 is a SharePoint Server vulnerability.
  • CVE-2026-65660 was initially classified as a spoofing flaw with a CVSS score of 6.5.
  • CVE-2026-65660 was re-evaluated as an authenticated remote code execution vulnerability.
  • Dinh Ho Anh Khoa re-evaluated CVE-2026-65660.
  • CVE-2026-65660 affects SharePoint Server 2016, 2019, and Subscription Edition.
  • Patches for CVE-2026-65660 have been available since August 11.
  • The National Vulnerability Database scores CVE-2026-65660 at 8.8.
  • Microsoft's advisory for CVE-2026-65660 describes it as allowing an authorized attacker to perform spoofing.
  • Microsoft's CVE record for CVE-2026-65660 was updated on September 11.
  • Both Microsoft records for CVE-2026-65660 assign CWE-94, a code-injection weakness.
  • Khoa demonstrated the ToolShell exploit chain at Pwn2Own Berlin in May 2025.
🕒 2026-09-09 · new reporting from The Record
  • Microsoft's latest Patch Tuesday addressed 973 vulnerabilities.
  • CISA mandated federal agencies patch CVE-2026-81963 and CVE-2026-85880 by September 22.
  • CVE-2026-81963 relates to a component used to install Windows updates.
  • CVE-2026-85880 affects a messaging system in Windows.
🕒 2026-09-08 · new reporting from SecurityWeek
  • Microsoft patched 974 vulnerabilities.
  • CVE-2026-85880 is a heap buffer overflow in Windows ALPC.
  • CVE-2026-85880 allows a local attacker to gain System privileges.
  • CVE-2026-85880 requires no user interaction.
  • CVE-2026-85880 is the second ALPC zero-day in nearly four years.
  • CVE-2026-81963 is an improper link resolution defect in Windows Update Stack.
  • CVE-2026-81963 allows local attackers to elevate privileges to System.
  • CVE-2026-81963 is the first Update Stack security weakness.
🕒 2026-09-01 · new reporting from BleepingComputer
  • 22,000 Microsoft Exchange servers are vulnerable to CVE-2026-62911.
  • CVE-2026-62911 is an authentication bypass vulnerability.
  • CVE-2026-62911 allows attackers to hijack user mailboxes.
  • CVE-2026-62911 affects Exchange Server 2016, 2019, and Subscription Edition.
  • CVE-2026-62911 was reported by DEVCORE Research Team's Orange Tsai.
  • CVE-2026-62911 requires basic privileges and user interaction for exploitation.
  • Microsoft patched CVE-2026-62911 during the August 2026 Patch Tuesday.
  • NCSC-NL reported exploit code for CVE-2026-62911 is available online.
🕒 2026-08-26 · new reporting from BleepingComputer
  • Threat actors are targeting a chain of CVE-2026-55040 and CVE-2026-63520.
  • CVE-2026-63520 is a vulnerability in SharePoint's Business Connectivity Services (BCS).
  • CVE-2026-63520 allows unauthenticated attackers to execute arbitrary code.
  • Stephen Fewer released a PoC for CVE-2026-55040 on August 11.
  • Jonathan Peterson released a PoC for CVE-2026-63520 on August 24.
  • Defused reported weaponization of CVE-2026-55040 PoC one day after its release.
🕒 2026-08-21 · new reporting from BleepingComputer
  • CVE-2026-69836 affects Entra ID, formerly Azure Active Directory.
  • CVE-2026-69836 allows unprivileged attackers to achieve code execution.
  • Microsoft fully mitigated CVE-2026-69836; no user action is required.
🕒 2026-08-21 · new reporting from The Hacker News, SecurityWeek
  • Microsoft patched CVE-2026-69836 in its Entra ID service.
  • CVE-2026-69836 has a CVSS score of 10.0.
  • CVE-2026-69836 is a deserialization of untrusted data vulnerability.
  • Microsoft credited Robert Fitzaptrick for discovering CVE-2026-69836.
  • Microsoft released 22 new security updates.
  • CVE-2026-69502 is an EoP bug in Azure SQL Database.
  • CVE-2026-69502 has a CVSS score of 10/10.
  • CVE-2026-69555 is an EoP bug in Azure Arc.
  • CVE-2026-69555 has a CVSS score of 10/10.
  • CVE-2026-65816 is an EoP bug in Azure Arc.
  • CVE-2026-65816 has a CVSS score of 10/10.
  • CVE-2026-65801 is an EoP bug in Exchange Online.
  • CVE-2026-65801 has a CVSS score of 10/10.
  • CVE-2026-65770 is an RCE flaw in Azure Managed Instance for Apache Cassandra.
  • CVE-2026-65770 has a CVSS score of 10/10.
  • CVE-2026-68782 is an EoP issue in Azure SQL Database.
  • CVE-2026-63509 is an EoP issue in Microsoft Fabric.
  • CVE-2026-69851 is an EoP issue in Entra ID.
  • CVE-2026-68789 is an EoP issue in Azure SQL Database.
  • CVE-2026-69400 is an EoP issue in Azure Logic Apps.
  • CVE-2026-62834 is an EoP issue in Azure Data Factor.
  • CVE-2026-66309 is an EoP issue in Azure SQL Database.
🕒 2026-08-19 · new reporting from BleepingComputer, SecurityWeek, The Hacker News
  • CISA warned of CVE-2026-33824, a critical RCE flaw in Windows IKE Service Extensions.
  • CVE-2026-33824 impacts Windows 10, Windows 11, and Windows Server releases.
  • CVE-2026-33824 allows unauthenticated attackers to execute code via UDP ports 500 or 4500.
  • Microsoft addressed CVE-2026-33824 during the April 2026 Patch Tuesday.
  • CVE-2026-33824 is a double free vulnerability.
  • CVE-2026-33824 has a CVSS score of 9.8.
  • Palo Alto Networks flagged CVE-2026-33824 as exploited by a Chinese-speaking threat actor.
  • CVE-2026-55040 was fixed on Microsoft's July 2026 Patch Tuesday.
  • Threat actors started targeting CVE-2026-55040 after a PoC exploit was published.
  • CISA added CVE-2026-59310 to its KEV catalog.
  • CVE-2026-65400 is an improper authentication vulnerability impacting Apple macOS.
  • CVE-2026-65400 allows an attacker to authenticate to Screen Sharing without valid credentials.
  • CVE-2026-65400 has a CVSS score of 9.8.
  • CVE-2026-59310 is a path traversal vulnerability in Broadcom VMware vCenter.
  • CVE-2026-59310 allows a threat actor with network access to vCenter to execute arbitrary code.
  • CVE-2026-59310 has a CVSS score of 9.8.
🕒 2026-08-18 · new reporting from BleepingComputer
  • Ransomware gangs exploit CVE-2025-60710.
  • CVE-2025-60710 is a Windows Task Host privilege escalation vulnerability.
  • CVE-2025-60710 allows attackers to gain SYSTEM privileges.
  • CVE-2025-60710 affects Windows 11 and Windows Server 2025.
  • CVE-2025-60710 was patched by Microsoft in November 2025.
  • CVE-2025-60710 stems from a link following weakness.
  • CISA added CVE-2025-60710 to its KEV catalog on April 13.
  • Federal agencies had two weeks to patch CVE-2025-60710.
🕒 2026-07-24 · new reporting from The Hacker News
  • CVE-2026-45659 has a CVSS score of 8.8.
  • CVE-2026-45659 was addressed by Microsoft in May 2026.
  • CVE-2026-45659 impacts SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
  • CVE-2026-45659 is a deserialization of untrusted data vulnerability.
  • CVE-2026-45659 requires Site Member permissions for exploitation.
  • CISA mandated federal agencies patch CVE-2026-45659 by July 4, 2026.
  • Microsoft patched a record 622 vulnerabilities.
  • CVE-2026-56164 is a privilege escalation flaw.
  • CVE-2026-56164 affects on-premises SharePoint Server.
  • CVE-2026-56164 was credited to Mandiant's incident responders and Google's FLARE team.
  • CISA warned of three actively exploited SharePoint vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164.
  • CVE-2026-32201 is a spoofing issue patched in April.
  • CVE-2026-55040 is a critical security bypass weakness.
  • CVE-2026-58644 has a CVSS score of 9.8.
  • CVE-2026-58644 allows an attacker authenticated as a Site Owner to execute code.
  • CISA mandated federal agencies patch CVE-2026-58644 by July 19, 2026.
  • CVE-2026-50522 has a CVSS score of 9.8.
  • CVE-2026-50522 was discovered by DEVCORE researcher "splitline".
  • CVE-2026-50522 allows an attacker authenticated as a Site Owner to execute code.
  • CVE-2026-50522 is being exploited to steal machine keys.
  • Defused observed exploitation attempts targeting CVE-2026-50522 on July 17.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Oct 01

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A remote code execution vulnerability in Microsoft SharePoint, CVE-2026-65660, is now being exploited in attacks, approximately six weeks after Microsoft released patches. The flaw allows an authenticated attacker with low-level access to execute arbitrary code without user interaction. This exploitation prompted CISA to add the vulnerability to its KEV catalog, requiring federal agencies to patch by September 28.

CISA has added two vulnerabilities, CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in MikroTik RouterOS, to its Known Exploited Vulnerabilities catalog. Both flaws are being actively exploited in the wild, posing significant risks to affected organizations.

CISA has issued a warning about active exploitation of critical vulnerabilities in WSO2 products and Adobe Commerce, alongside high-severity flaws in Microsoft SharePoint and Mikrotik RouterOS. Federal agencies must apply updates for the critical issues by September 27, as these vulnerabilities could lead to administrative account compromise and unauthorized access.

A SharePoint Server vulnerability, CVE-2026-65660, initially classified by Microsoft as a spoofing flaw, has been re-evaluated by a security researcher as an authenticated remote code execution (RCE) vulnerability. This reclassification significantly increases the severity of the flaw, affecting SharePoint Server 2016, 2019, and Subscription Edition, and highlights a discrepancy in Microsoft's initial assessment.

Microsoft's latest Patch Tuesday release addressed 973 vulnerabilities, a new record, with the CISA confirming that two of these, CVE-2026-81963 and CVE-2026-85880, are currently being exploited. Federal agencies must patch these exploited vulnerabilities by September 22. This large volume of disclosed bugs, exceeding 2,600 for the year, raises concerns about the increasing attack surface and the potential for chained exploits.

Microsoft released a record 974 patches for its products, addressing two zero-day vulnerabilities actively exploited in the wild. These patches are critical for system security, as the zero-days allowed local privilege escalation.

Approximately 22,000 Microsoft Exchange servers exposed online are still unpatched against a high-severity authentication bypass vulnerability, CVE-2026-62911, which allows attackers to hijack user mailboxes. This vulnerability affects Exchange Server 2016, 2019, and Subscription Edition, posing a significant risk to organizations that have not applied the August 2026 Patch Tuesday updates.

Threat actors are actively targeting a chain of two Microsoft SharePoint vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution on unpatched servers. This exploitation chain allows attackers to bypass authentication and then execute arbitrary code, posing a significant risk to organizations using vulnerable SharePoint installations.

Microsoft has patched a maximum-severity vulnerability, CVE-2026-69836, in its Entra ID identity and access management platform, which was actively exploited in attacks. This flaw allowed unprivileged attackers to achieve code execution over a network, but Microsoft states no user action is required as the mitigation is complete.

Microsoft released 22 new security updates addressing critical and high-severity vulnerabilities across multiple products, including Azure, Entra ID, and Exchange. These patches resolve issues like elevation of privilege and remote code execution flaws, with some having a CVSS score of 10/10. The updates are significant for maintaining the security posture of Microsoft's cloud services and enterprise products, as many of the vulnerabilities could lead to severe system compromise.

Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in its Entra ID service, which was actively exploited. The flaw, rated 10.0 CVSS, allowed unauthorized attackers to execute code over a network, but Microsoft states no customer action is required as it has been fully mitigated.

CISA has added four critical vulnerabilities affecting Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft Internet Key Exchange (IKE) to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These flaws allow for unauthorized access, code execution, and bypass of security features, posing significant risks to affected systems globally.

The US Cybersecurity and Infrastructure Infrastructure Security Agency (CISA) has issued an urgent warning for organizations to patch four actively exploited vulnerabilities in Microsoft, VMware, and Apple products. These flaws include critical remote code execution and authentication bypass issues that threat actors are already leveraging in attacks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that a critical remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component (CVE-2026-33824) is being actively exploited by attackers. This vulnerability allows unauthenticated attackers to execute code on unpatched Windows systems, posing a significant risk to federal agencies and other organizations.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting CVE-2025-60710, a high-severity Windows Task Host privilege escalation vulnerability. This exploitation allows attackers to gain SYSTEM privileges on unpatched Windows 11 and Windows Server 2025 devices, posing a significant risk to federal agencies and other organizations.

Threat actors are exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint, following the public release of a proof-of-concept (PoC) exploit. This vulnerability allows unauthenticated attackers to impersonate users or administrators and access or modify data on vulnerable SharePoint servers.

A SharePoint vulnerability, CVE-2026-55040, patched by Microsoft in July, is now being actively exploited in the wild, with attacks emerging shortly after a public proof-of-concept (PoC) exploit was released. This exploitation allows unauthenticated attackers to bypass security features, potentially leading to file disclosure and data modification in SharePoint instances.

Microsoft's August Patch Tuesday update addresses 421 vulnerabilities across its products, including a Windows zero-day flaw that has been actively exploited. This update is critical for Windows users as the exploited vulnerability allows attackers to gain system privileges without user interaction after an initial intrusion.

A critical authentication bypass vulnerability in Microsoft SharePoint, CVE-2026-55040, is being exploited in attacks after a proof-of-concept (PoC) exploit was published by Rapid7. This flaw allows unprivileged attackers to impersonate SharePoint users or administrators, potentially leading to file disclosure and data modification.

Microsoft released its monthly security updates, addressing 398 vulnerabilities, including a Windows kernel driver flaw (CVE-2026-68820) that is actively being exploited for privilege escalation. The update also includes patches for four critical remote code execution flaws with CVSS scores of 9.8 that do not require user interaction. This update is significant as it addresses an actively exploited vulnerability and numerous other critical issues, requiring immediate attention from system administrators.

Microsoft released patches for 421 vulnerabilities in its August 2026 Patch Tuesday update, including a high-severity zero-day vulnerability (CVE-2026-68820) in the Ancillary Function Driver for WinSock that is actively being exploited. This update is critical for Windows users as it addresses privilege escalation flaws, some of which are publicly disclosed and likely to be exploited.

Security researchers, using AI assistance, discovered a critical exploit chain in Microsoft SharePoint servers (CVE-2026-55040 and CVE-2026-63520) that allows unauthenticated remote code execution. This vulnerability affects SharePoint Server Subscription Edition, 2019, and 2016, enabling attackers to assume any user's identity, including administrators, and run code on the server.

The Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability, CVE-2026-45659. This flaw allows low-privileged attackers to execute arbitrary code on unpatched SharePoint servers, posing a significant risk to organizations using the software.

Microsoft patched over a dozen vulnerabilities across its products, including critical remote code execution and elevation of privilege issues. Apple released an update for a single bug that could bypass Screen Sharing authentication. These updates address security flaws that could be exploited over networks, impacting user security across various platforms.

The Swiss Federal Office for Information Technology and Telecommunication (BIT) reported a breach of its Microsoft SharePoint servers, compromising approximately 200 accounts. This incident highlights the ongoing risk posed by unpatched vulnerabilities, as the attackers likely exploited flaws disclosed and fixed by Microsoft in mid-July.

Switzerland's Federal Office for Information Technology and Communications (BIT) disclosed that hackers compromised approximately 200 accounts on its on-premises SharePoint servers. The agency suspects the attack exploited vulnerabilities identified in July's Patch Tuesday, which are also listed in CISA's Known Exploited Vulnerabilities catalog. This incident highlights the ongoing risk associated with SharePoint vulnerabilities, particularly for organizations exposing the service directly to the internet.

A proof-of-concept exploit for "Certighost" (CVE-2026-54121), a vulnerability in Windows Active Directory Certificate Services, has been publicly released. This exploit allows authenticated attackers to potentially compromise a Windows domain by impersonating a Domain Controller and performing privileged Active Directory operations.

Security researchers published a working exploit, dubbed Certighost, that allows a low-privileged Active Directory user to obtain a certificate for a Domain Controller and authenticate as that machine. This exploit leverages a flaw in Active Directory Certificate Services (AD CS) that Microsoft patched as CVE-2026-54121, enabling attackers to potentially retrieve the krbtgt secret through DCSync.

Check Point released security updates for its Security Management and Multi-Domain Management products, addressing multiple vulnerabilities including one actively exploited in the wild. The critical flaw, CVE-2026-16232, allowed unauthenticated remote attackers to gain full administrative privileges on SmartConsole. This impacts customers with management servers exposed directly to the internet without IP restrictions, enabling attackers to modify security policies and configurations.

Another SharePoint vulnerability, CVE-2026-50522, has been exploited in the wild, marking the fourth such case in a month. This critical flaw allows remote code execution and has been confirmed by multiple security firms as a significant risk to affected organizations.

Hackers are exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys, enabling long-term unauthorized access to affected servers. Microsoft had previously issued patches for this deserialization flaw, but with the public release of proof-of-concept exploit code, attackers began targeting vulnerable installations immediately.

CVE-2026-50522 in Microsoft SharePoint Server, with a CVSS score of 9.8, is actively being exploited following the release of a public proof-of-concept exploit. This vulnerability allows an attacker with Site Owner credentials to execute arbitrary code remotely, posing significant risks to on-premises SharePoint deployments.

CISA reports ongoing exploitation of the critical RCE vulnerability CVE-2026-58644 in Microsoft SharePoint. This flaw has a CVSS score of 9.8 and allows attackers to execute arbitrary code, prompting urgent patching recommendations for federal agencies.

CISA has included CVE-2026-58644, a critical zero-day vulnerability in Microsoft SharePoint, in its Known Exploited Vulnerabilities catalog. Agencies must implement fixes by July 19, 2026, following reports of active exploitation.

CISA has directed federal agencies to patch a critical vulnerability in Oracle E-Business Suite by July 18 due to ongoing exploitation. The vulnerability allows unauthenticated attackers to gain control of systems, highlighting significant risks in federal cybersecurity.

CISA has urged immediate patching of multiple zero-day vulnerabilities in Microsoft SharePoint, including newly disclosed CVE-2026-56164. These critical vulnerabilities pose serious risks for organizations if not addressed promptly, particularly in potential remote code execution scenarios.

CISA has issued a warning regarding three actively exploited vulnerabilities in on-premises SharePoint Server instances. This is significant as exploited vulnerabilities could allow attackers to execute remote code, steal sensitive keys, and deploy malware on affected systems.

Microsoft released its largest Patch Tuesday ever, addressing 622 vulnerabilities, including two zero-days being actively exploited in the wild. The critical patches for SharePoint Server and Active Directory Federation Services are essential due to their potential for privilege escalation attacks.

Microsoft released patches for 622 vulnerabilities, including two zero-days in Active Directory and SharePoint Server. The fixes address critical security flaws, significantly enhancing protection for users and organizations against potential exploits.

CISA has confirmed that a high-severity remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-45659, is being actively exploited. This flaw allows low-privileged authenticated attackers to execute arbitrary code on vulnerable servers, posing significant risks especially for federal agencies that must secure their systems by a mandated deadline.

CISA has identified a high-severity vulnerability (CVE-2026-45659) in Microsoft SharePoint Server being actively exploited by threat actors. This flaw allows attackers with site member permissions to execute arbitrary code, emphasizing the need for urgent patching by organizations.

CISA added CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw allows authenticated attackers to execute code without elevated privileges, impacting network security for federal agencies required to apply patches by July 4, 2026.