sharepoint news
8 stories
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
The Warlock ransomware group, tracked by Symantec as Longlegs and also known as Storm-2603, continues to exploit unpatched vulnerabilities in Microsoft SharePoint, more than a year after these flaws were initially publicized. The group, which has historical ties to China-nexus clusters CL-CRI-1040, CamoFei, and ChamelGang, has recently targeted critical infrastructure, including water…

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
A Chinese threat group is reportedly deploying "Warlock" ransomware in attacks targeting critical infrastructure organizations in Portuguese and Spanish-speaking countries. The campaign exploits various vulnerabilities within Microsoft SharePoint, according to recent analysis from the Symantec Threat Hunter Team.

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
A remote code execution (RCE) vulnerability, identified as CVE-2026-63520, has been disclosed in Microsoft SharePoint, allowing an authenticated attacker to execute arbitrary code on a vulnerable server. When chained with an authentication bypass vulnerability, CVE-2026-55040, the exploit becomes unauthenticated.

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Attackers have begun exploiting a critical authentication bypass vulnerability in Microsoft SharePoint, designated CVE-2026-55040, following the public release of a proof-of-concept (PoC) exploit. The flaw, which carries a CVSS score of 9.1, allows unauthenticated attackers to impersonate any SharePoint user, including administrators.

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability, identified as CVE-2026-55040, according to recent reports. This exploitation campaign began shortly after a proof-of-concept (PoC) exploit for the flaw was publicly released. The vulnerability is described as a security feature bypass, enabling unauthenticated attackers to impersonate legitimate users within…

CISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to address them by July 19, 2026. The newly listed flaws include one affecting Microsoft SharePoint and two impacting Fortinet FortiSandbox products.

Microsoft SharePoint Server RCE Vulnerability Exploited in the Wild
Microsoft has confirmed active exploitation of a critical remote code execution (RCE) vulnerability, CVE-2026-58644, affecting on-premises deployments of its SharePoint Server. The vulnerability, which stems from the deserialization of untrusted data (CWE-502), allows an unauthenticated attacker to execute arbitrary code with a CVSS v3.1 score of 9.8 (Critical).

New Helix Group Targets SharePoint Data via Vishing and MFA Abuse
A new data extortion group, dubbed Helix, has emerged, employing voice phishing (vishing) and multi-factor authentication (MFA) abuse to compromise SharePoint environments and exfiltrate data. The group's primary objective is to extort victim organizations by threatening to publish stolen information or sell it to other cybercriminals.