Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Filtered Reports
2 / 2 results
criticalbug_reportVulnerabilitybug_reportVulnerability
SharePoint CVE-2026-55040 exploited in wild after PoC release
Microsoft SharePoint servers not patched with July 2026 Patch Tuesday updates. All unpatched SharePoint instances are vulnerable to authentication bypass allowing unauthenticated remote attackers to impersonate any site user or administrator.
CVE-2026-5504013 Aug · 04:09 UTC
criticalbug_reportVulnerabilitybug_reportVulnerability
SharePoint Server auth bypass chained to RCE, no credentials required
Microsoft SharePoint Server Subscription Edition, 2019, and 2016 (CVE-2026-55040, CVSS 9.1). Chained RCE flaw CVE-2026-63520 (CVSS 8.1) also affects Project Server 2013 SP1 and Office Web Apps 2013 SP1. SharePoint Online is not affected.
CVE-2026-5504011 Aug · 14:47 UTC