Microsoft News Articles

Recent news articles refferecing the vendors vulnerabilities.

Microsoft Exchange Exploit Requires No Password: 22,000 Servers Exposed, ESU Ends October

CVE-2026-62911 Exchange Server flaw lets attackers seize all mailboxes with no password: nearly 22,000 servers remain unpatched worldwide three weeks after Microsoft’s August fix shipped, 85 percent

21 hours ago

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - IT Security News

2026-09-02 15:09 Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the...

21 hours ago

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - Help Net Security

Nearly 22,000 Microsoft Exchange servers stay exposed to CVE-2026-62911, a high-severity flaw with public exploit code online.

21 hours ago

Nearly 22,000 Exchange Servers Are Still Vulnerable Despite Microsoft’s August Patch

Nearly 22,000 Microsoft Exchange servers remain vulnerable to CVE-2026-62911, with public exploit code already available.

2 days ago

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.

2 days ago

Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability - IT Security News

2026-09-01 14:09 A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness....

2 days ago

Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability

Public PoC released for CVE-2026-62911, an Exchange Server authentication capture-and-replay flaw.

2 days ago

Microsoft SharePoint Exploit Chain: Why the Latest RCE Flaw Matters

Microsoft SharePoint is under active attack via an exploit chain that combines authentication bypass and RCE flaws. Here’s what organizations need to know.

5 days ago

Two SharePoint Flaws Give Hackers a Path to Remote Code Execution

Hackers are probing a Microsoft SharePoint exploit chain that combines CVE-2026-55040 and CVE-2026-63520 for potential remote code execution.

1 week ago

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.

1 week ago

Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Microsoft SharePoint flaws can be chained to bypass authentication and remotely take control of vulnerable servers without a password.

1 week ago

Microsoft Patches Entra ID RCE Vulnerability Exploited in Attacks  | eSecurity Planet

Microsoft patched an Entra ID RCE vulnerability exploited in attacks that required no authentication or user interaction.

2 weeks ago

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - IT Security News

2026-08-21 14:08 Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity...

2 weeks ago

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - Help Net Security

Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild.

2 weeks ago

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks.

2 weeks ago

Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack

Redmond says the cloud identity bug is already fixed, but isn't saying who exploited it or how widely

2 weeks ago

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft says CVE-2026-69836, a CVSS 10.0 Entra ID RCE flaw, has been exploited in the wild but is fully mitigated with no user action required.

2 weeks ago

Microsoft Entra ID Remote Code Execution Vulnerability Exploited in the Wild

Microsoft has confirmed that a critical remote code execution flaw in Entra ID, its cloud-based identity and access management platform, has already been exploited in the wild.

2 weeks ago

That April Windows update you skipped? Hackers are exploiting it now

CISA has confirmed active attacks on Windows, macOS, and VMware vulnerabilities. Here's what home users and IT admins need to patch immediately.

2 weeks ago

Critical RCE flaw in Windows IKE Extension now actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component.

2 weeks ago

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

CVE-2026-24301 lets crafted Copilot Personal links auto-run prompts that can pull data from connected apps and exfiltrate it via URL fetches.

2 weeks ago

CISA: Windows Task Host flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.

2 weeks ago

Public Exploit Code Released for Microsoft SCCM Remote Code Execution Vulnerability

Public PoC code for critical SCCM RCE vulnerability CVE-2026-47301 could let low-privileged domain users gain SYSTEM access on Primary Site Servers.

2 weeks ago

Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been.

2 weeks ago

No more news articles to load.