Microsoft News Articles
Recent news articles refferecing the vendors vulnerabilities.
Microsoft Exchange Exploit Requires No Password: 22,000 Servers Exposed, ESU Ends October
CVE-2026-62911 Exchange Server flaw lets attackers seize all mailboxes with no password: nearly 22,000 servers remain unpatched worldwide three weeks after Microsoft’s August fix shipped, 85 percent
21 hours ago
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - IT Security News
2026-09-02 15:09 Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the...
21 hours ago
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - Help Net Security
Nearly 22,000 Microsoft Exchange servers stay exposed to CVE-2026-62911, a high-severity flaw with public exploit code online.
21 hours ago
Nearly 22,000 Exchange Servers Are Still Vulnerable Despite Microsoft’s August Patch
Nearly 22,000 Microsoft Exchange servers remain vulnerable to CVE-2026-62911, with public exploit code already available.
2 days ago
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.
2 days ago
Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability - IT Security News
2026-09-01 14:09 A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness....
2 days ago
Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability
Public PoC released for CVE-2026-62911, an Exchange Server authentication capture-and-replay flaw.
2 days ago

Microsoft SharePoint Exploit Chain: Why the Latest RCE Flaw Matters
Microsoft SharePoint is under active attack via an exploit chain that combines authentication bypass and RCE flaws. Here’s what organizations need to know.
5 days ago
Two SharePoint Flaws Give Hackers a Path to Remote Code Execution
Hackers are probing a Microsoft SharePoint exploit chain that combines CVE-2026-55040 and CVE-2026-63520 for potential remote code execution.
1 week ago
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.
1 week ago
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password
Microsoft SharePoint flaws can be chained to bypass authentication and remotely take control of vulnerable servers without a password.
1 week ago

Microsoft Patches Entra ID RCE Vulnerability Exploited in Attacks | eSecurity Planet
Microsoft patched an Entra ID RCE vulnerability exploited in attacks that required no authentication or user interaction.
2 weeks ago
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - IT Security News
2026-08-21 14:08 Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity...
2 weeks ago
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - Help Net Security
Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild.
2 weeks ago
Microsoft warns of max severity Entra ID flaw exploited in attacks
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks.
2 weeks ago
Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack
Redmond says the cloud identity bug is already fixed, but isn't saying who exploited it or how widely
2 weeks ago
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft says CVE-2026-69836, a CVSS 10.0 Entra ID RCE flaw, has been exploited in the wild but is fully mitigated with no user action required.
2 weeks ago
Microsoft Entra ID Remote Code Execution Vulnerability Exploited in the Wild
Microsoft has confirmed that a critical remote code execution flaw in Entra ID, its cloud-based identity and access management platform, has already been exploited in the wild.
2 weeks ago
That April Windows update you skipped? Hackers are exploiting it now
CISA has confirmed active attacks on Windows, macOS, and VMware vulnerabilities. Here's what home users and IT admins need to patch immediately.
2 weeks ago
Critical RCE flaw in Windows IKE Extension now actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component.
2 weeks ago
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
CVE-2026-24301 lets crafted Copilot Personal links auto-run prompts that can pull data from connected apps and exfiltrate it via URL fetches.
2 weeks ago
CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
2 weeks ago
Public Exploit Code Released for Microsoft SCCM Remote Code Execution Vulnerability
Public PoC code for critical SCCM RCE vulnerability CVE-2026-47301 could let low-privileged domain users gain SYSTEM access on Primary Site Servers.
2 weeks ago

Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been.
2 weeks ago