Skip to content
Threat Feed

Tag

Sharepoint

13 briefs RSS
critical threat

Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday

Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.

exploited PoC Active Directory Federation Services +23 patch-tuesday zero-day vulnerability microsoft windows sharepoint active-directory-federation-services bitlocker +2
8t 4c 8i updated
high advisory

Microsoft SharePoint Server RCE Vulnerability

An authenticated remote attacker can exploit a vulnerability in Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint to execute arbitrary code.

SharePoint Server 2016 +2 sharepoint rce code_execution
2r 1t
high advisory

CVE-2026-40368 - Microsoft Office SharePoint Deserialization Vulnerability

CVE-2026-40368 is a deserialization of untrusted data vulnerability in Microsoft Office SharePoint, allowing an authorized attacker to execute code over a network.

Office SharePoint deserialization code-execution sharepoint
2r 1t 1c
high advisory

CVE-2026-33110 - Microsoft SharePoint Deserialization Vulnerability

CVE-2026-33110 is a deserialization of untrusted data vulnerability in Microsoft Office SharePoint, allowing an authorized attacker to achieve remote code execution over a network.

Office SharePoint cve deserialization rce sharepoint
1r 1t 1c
critical advisory

Critical Unauthenticated RCE Vulnerability Exploited in Microsoft SharePoint

A remote code execution vulnerability in Microsoft SharePoint (CVE not specified) is being actively exploited by unauthenticated attackers, prompting urgent patching recommendations for internet-facing servers.

sharepoint rce vulnerability
2r 2t
critical advisory

Active Exploitation of SharePoint Deserialization Vulnerability (CVE-2026-20963)

CVE-2026-20963, a SharePoint deserialization vulnerability, is under active exploitation and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, requiring immediate patching and auditing of potentially compromised data.

CVE-2026-20963 sharepoint deserialization cisa-kev
2r 1t
high advisory

SharePoint Malware Upload for Lateral Movement

Attackers can upload malware to SharePoint, leveraging the platform's file-sharing capabilities to propagate threats laterally within an organization and compromise additional systems.

SharePoint +1 lateral-movement malware o365
2r 2t
high advisory

SharePoint spinstall0.aspx Webshell Activity

This brief describes the detection of GET requests to the spinstall0.aspx webshell, commonly deployed after exploiting CVE-2025-53770 in Microsoft SharePoint, indicating potential command execution, data exfiltration, or credential harvesting.

SharePoint webshell cve-2025-53770 t1190 t1505.003 t1552
2r 3t
medium advisory

SharePoint Sensitive Term Discovery via O365 Logs

Adversaries may search for sensitive terms within SharePoint to identify valuable data for exfiltration or further compromise, leaving traces in O365 audit logs.

SharePoint +1 discovery sensitive-data o365
2r 1t
medium advisory

M365 SharePoint/OneDrive File Access via PowerShell

Detects file downloads and access from OneDrive or SharePoint using PowerShell-based user agents, which adversaries leverage with compromised OAuth tokens to exfiltrate data.

Microsoft 365 +2 cloud saas microsoft365 sharepoint onedrive powershell
2r 4t
medium advisory

Entra ID Sharepoint or OneDrive Accessed by Unusual Client

An application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.

Entra ID +2 azure sharepoint onedrive oauth phishing illicit-consent
2r 4t
high advisory

Spring Boot Actuator Misconfiguration Leads to Potential SharePoint Exfiltration via Stolen Credentials

A threat actor can exploit a misconfigured Spring Boot Actuator to steal credentials and potentially exfiltrate data from SharePoint after bypassing MFA.

Spring Boot +1 spring-boot actuator sharepoint credential-theft data-exfiltration
2r 4t 1i
critical advisory

Microsoft SharePoint Server Elevation of Privilege via CVE-2023-29357

Exploitation attempts against Microsoft SharePoint Server vulnerability CVE-2023-29357, involving specific API calls and HTTP methods, can lead to privilege escalation and unauthorized access to sensitive data within the SharePoint environment.

SharePoint Server sharepoint elevation_of_privilege cve-2023-29357
2r 1t