The Cybersecurity and Infrastructure Security Agency (CISA) confirmed that attackers are actively exploiting a high-severity remote code execution vulnerability in Microsoft SharePoint that was patched in May.
CISA's warning, issued Wednesday, indicates that the vulnerability has moved from theoretical threat to active exploitation in the wild. The flaw allows attackers to execute arbitrary code remotely on vulnerable SharePoint instances, potentially granting them full system access.
Microsoft addressed the vulnerability in its May security update, but organizations that failed to apply the patch remain at risk. The company initially rated the flaw as important; however, active exploitation has elevated its practical severity.
The vulnerability affects multiple versions of SharePoint Server, making it a broad target for attackers seeking to compromise enterprise environments. Successful exploitation could allow adversaries to steal sensitive data, deploy malware, or establish persistent access within an organization's network.
CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, a list of flaws actively being weaponized by threat actors. This designation typically prompts federal agencies to prioritize patching within their networks.
Security researchers recommend organizations immediately verify whether SharePoint systems have received the May update. For environments where patching is delayed, CISA suggests implementing network segmentation and monitoring for suspicious SharePoint activity.
The exploitation campaign's scope remains unclear, though CISA's public warning suggests the vulnerability poses sufficient risk to warrant urgent action across government and critical infrastructure sectors. Organizations should treat this as a priority patching event rather than a routine update.
This incident underscores the importance of timely patch management. Defenders typically have a limited window to deploy fixes before threat actors weaponize disclosed vulnerabilities. The longer an organization delays patching, the greater its exposure to active exploitation campaigns.
Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.
A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.
McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.