Attackers exploit Microsoft SharePoint vulnerabilities with active PoC
On August 26, 2026, threat intelligence firm Defused reported that attackers were actively exploiting a chain of two Microsoft SharePoint vulnerabilities enabling remote code execution on unpatched servers. The disclosure included proof-of-concept exploit code.