Microsoft News Articles
Recent news articles refferecing the vendors vulnerabilities.
Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges
Microsoft has confirmed a high-severity remote code execution vulnerability in on-premises SharePoint Server that lets an authenticated, low-privileged attacker run arbitrary code over a network without user interaction.
1 day ago

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
SharePoint CVE-2026-65660 enables authenticated RCE; Microsoft patched it on August 11, and no in-the-wild exploitation is reported.
1 day ago
Windows COM Flaw Lets Attackers Gain SYSTEM Privileges With a Malicious DLL
A newly detailed Windows privilege escalation flaw tracked as CVE-2026-66804 allowed a standard, low-privileged user to plant a malicious DLL and execute arbitrary code with full NT AUTHORITYSYSTEM privileges, exploiting a lingering weakness in how Windows handles Component Object Model (COM) regist...
1 day ago

Microsoft Defender Falls Into a Patch-and-Bypass Cycle
A researcher says ShieldCrash bypasses Microsoft’s latest Defender fix, extending a patch-and-bypass chain involving RoguePlanet and ShieldBreak.
2 weeks ago
ShieldCrash exploit claims Microsoft Defender bypass
A researcher released ShieldCrash on September 8, claiming it bypasses Microsoft's Defender fix for flaw CVE-2026-69414. Microsoft hasn't confirmed it.
2 weeks ago
Microsoft Fixes 974 Flaws in Record Patch Tuesday
Microsoft’s record September Patch Tuesday fixes 974 vulnerabilities, including two exploited zero-days. Here’s what IT teams should prioritize.
2 weeks ago
New Windows Defender ShieldCrash 0-Day Bypasses Microsoft Patch to Read Files as SYSTEM
ShieldCrash claims Microsoft Defender remains vulnerable to arbitrary file reads with SYSTEM privileges, despite the CVE-2026-69414 fix.
2 weeks ago

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor - Help Net Security
On September 2026 Patch Tuesday Microsoft delivered a record-breaking number of patches, including for two bugs exploited as zero-days.
2 weeks ago
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
A Microsoft Defender patch bypass PoC demonstrates arbitrary file read as SYSTEM on the latest Windows version.
2 weeks ago
Hundreds of old, vulnerable Exchange servers remain in Australia
Key points 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft's fix. Working exploit code is now publicly available, and...
2 weeks ago
Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers
2 weeks ago
Critical Exchange bypass flaw leaves 22,000 servers open
CVE-2026-62911, a critical Exchange authentication-bypass flaw, still exposes ~22,000 servers as a working exploit circulates despite an August patch.
3 weeks ago
Microsoft Exchange Exploit Requires No Password: 22,000 Servers Exposed, ESU Ends October
CVE-2026-62911 Exchange Server flaw lets attackers seize all mailboxes with no password: nearly 22,000 servers remain unpatched worldwide three weeks after Microsoft’s August fix shipped, 85 percent
3 weeks ago
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - IT Security News
2026-09-02 15:09 Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the...
3 weeks ago
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - Help Net Security
Nearly 22,000 Microsoft Exchange servers stay exposed to CVE-2026-62911, a high-severity flaw with public exploit code online.
3 weeks ago
Nearly 22,000 Exchange Servers Are Still Vulnerable Despite Microsoft’s August Patch
Nearly 22,000 Microsoft Exchange servers remain vulnerable to CVE-2026-62911, with public exploit code already available.
3 weeks ago
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.
3 weeks ago
Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability - IT Security News
2026-09-01 14:09 A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness....
3 weeks ago
Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability
Public PoC released for CVE-2026-62911, an Exchange Server authentication capture-and-replay flaw.
3 weeks ago

Microsoft SharePoint Exploit Chain: Why the Latest RCE Flaw Matters
Microsoft SharePoint is under active attack via an exploit chain that combines authentication bypass and RCE flaws. Here’s what organizations need to know.
4 weeks ago
Two SharePoint Flaws Give Hackers a Path to Remote Code Execution
Hackers are probing a Microsoft SharePoint exploit chain that combines CVE-2026-55040 and CVE-2026-63520 for potential remote code execution.
1 month ago
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.
1 month ago
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password
Microsoft SharePoint flaws can be chained to bypass authentication and remotely take control of vulnerable servers without a password.
1 month ago
