Microsoft has confirmed the active exploitation of CVE-2026-56155, an elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS). This flaw allows authenticated local attackers with low…
A critical remote code execution vulnerability (CVE-2026-50522) in Microsoft SharePoint is being actively exploited. Attackers are targeting on-premise SharePoint deployments to extract IIS machine keys, allowing for…
CISA has confirmed that ransomware groups are actively exploiting a critical vulnerability (CVE-2026-45659) in Microsoft SharePoint Server, which allows remote code execution. Over 200 unpatched SharePoint servers are…
Microsoft released security updates for SharePoint Enterprise Server 2016 and SharePoint Server 2019 to address CVE-2025-49706. The updates were published on July 8, 2025, and are critical for users running these…