Microsoft News Articles

Recent news articles refferecing the vendors vulnerabilities.

Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges

Microsoft has confirmed a high-severity remote code execution vulnerability in on-premises SharePoint Server that lets an authenticated, low-privileged attacker run arbitrary code over a network without user interaction.

1 day ago

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

SharePoint CVE-2026-65660 enables authenticated RCE; Microsoft patched it on August 11, and no in-the-wild exploitation is reported.

1 day ago

Windows COM Flaw Lets Attackers Gain SYSTEM Privileges With a Malicious DLL

A newly detailed Windows privilege escalation flaw tracked as CVE-2026-66804 allowed a standard, low-privileged user to plant a malicious DLL and execute arbitrary code with full NT AUTHORITYSYSTEM privileges, exploiting a lingering weakness in how Windows handles Component Object Model (COM) regist...

1 day ago

Microsoft Defender Falls Into a Patch-and-Bypass Cycle

A researcher says ShieldCrash bypasses Microsoft’s latest Defender fix, extending a patch-and-bypass chain involving RoguePlanet and ShieldBreak.

2 weeks ago

ShieldCrash exploit claims Microsoft Defender bypass

A researcher released ShieldCrash on September 8, claiming it bypasses Microsoft's Defender fix for flaw CVE-2026-69414. Microsoft hasn't confirmed it.

2 weeks ago

Microsoft Fixes 974 Flaws in Record Patch Tuesday

Microsoft’s record September Patch Tuesday fixes 974 vulnerabilities, including two exploited zero-days. Here’s what IT teams should prioritize.

2 weeks ago

New Windows Defender ShieldCrash 0-Day Bypasses Microsoft Patch to Read Files as SYSTEM

ShieldCrash claims Microsoft Defender remains vulnerable to arbitrary file reads with SYSTEM privileges, despite the CVE-2026-69414 fix.

2 weeks ago

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor - Help Net Security

On September 2026 Patch Tuesday Microsoft delivered a record-breaking number of patches, including for two bugs exploited as zero-days.

2 weeks ago

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

A Microsoft Defender patch bypass PoC demonstrates arbitrary file read as SYSTEM on the latest Windows version.

2 weeks ago

Hundreds of old, vulnerable Exchange servers remain in Australia

Key points 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft's fix. Working exploit code is now publicly available, and...

2 weeks ago

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers

2 weeks ago

Critical Exchange bypass flaw leaves 22,000 servers open

CVE-2026-62911, a critical Exchange authentication-bypass flaw, still exposes ~22,000 servers as a working exploit circulates despite an August patch.

3 weeks ago

Microsoft Exchange Exploit Requires No Password: 22,000 Servers Exposed, ESU Ends October

CVE-2026-62911 Exchange Server flaw lets attackers seize all mailboxes with no password: nearly 22,000 servers remain unpatched worldwide three weeks after Microsoft’s August fix shipped, 85 percent

3 weeks ago

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - IT Security News

2026-09-02 15:09 Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the...

3 weeks ago

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - Help Net Security

Nearly 22,000 Microsoft Exchange servers stay exposed to CVE-2026-62911, a high-severity flaw with public exploit code online.

3 weeks ago

Nearly 22,000 Exchange Servers Are Still Vulnerable Despite Microsoft’s August Patch

Nearly 22,000 Microsoft Exchange servers remain vulnerable to CVE-2026-62911, with public exploit code already available.

3 weeks ago

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.

3 weeks ago

Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability - IT Security News

2026-09-01 14:09 A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness....

3 weeks ago

Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability

Public PoC released for CVE-2026-62911, an Exchange Server authentication capture-and-replay flaw.

3 weeks ago

Microsoft SharePoint Exploit Chain: Why the Latest RCE Flaw Matters

Microsoft SharePoint is under active attack via an exploit chain that combines authentication bypass and RCE flaws. Here’s what organizations need to know.

4 weeks ago

Two SharePoint Flaws Give Hackers a Path to Remote Code Execution

Hackers are probing a Microsoft SharePoint exploit chain that combines CVE-2026-55040 and CVE-2026-63520 for potential remote code execution.

1 month ago

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.

1 month ago

Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Microsoft SharePoint flaws can be chained to bypass authentication and remotely take control of vulnerable servers without a password.

1 month ago

No more news articles to load.