Dossier
Microsoft SharePoint
Coverage of Microsoft SharePoint in the Nexus archive.
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors are exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS score: 9.1), after the release of a public proof-of-concept code. This critical flaw involves weak authentication and was patched by Microsoft during its July 2026 Patch Tuesday updates.
- Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks
Over 1,300 Microsoft SharePoint servers remain unpatched against a spoofing vulnerability, which was exploited as a zero-day and is still being used in ongoing attacks. The vulnerability allows attackers to spoof SharePoint servers, exposing sensitive data and systems to potential breaches.