Attackers exploit Microsoft SharePoint vulnerabilities with active PoC

On August 26, 2026, threat intelligence firm Defused reported that attackers were actively exploiting a chain of two Microsoft SharePoint vulnerabilities enabling remote code execution on unpatched servers. The disclosure included proof-of-concept exploit code.

2 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. ht

mastodon:infosec-exchangeother34d ago kagi ↗

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. https://www. bleepingcomputer.com/news/secu rity/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/