Channel created
Channel photo updated
🚨 CVE-2026-45659 — SharePoint Server RCE (CVSS 8.8)

Confirmed actively exploited. Added to CISA's Known Exploited Vulnerabilities catalog on July 1.

Microsoft patched this quietly in May — the security bulletin wasn't published until three weeks later. Root cause: unsafe deserialization. An attacker only needs Site Member access, not admin.

Affected: SharePoint Server Subscription Edition, 2019, and Enterprise 2016.

Full breakdown + patch guidance:
https://exploitgrid.net/blogs/cve-2026-45659-sharepoint-rce-active-exploitation

#CVE #SharePoint #CISAKEV #VulnerabilityManagement
🔴 CVE-2026-56155 — AD FS Privilege Escalation, Actively Exploited
Local attacker with low privileges → admin, on Microsoft AD FS servers. CVSS 7.8. Microsoft confirmed exploitation in the wild; ZDI says it chains well with RCE for ransomware. No public PoC yet, but that hasn't stopped active use.
Affected: AD FS on Windows Server 2012–2025 and related Server Core builds.

Full writeup: https://exploitgrid.net/blogs/cve-2026-56155-ad-fs-privilege-escalation-bug-is-already-being-exploited

#ADFS #CISAKEV