Article may be outdated

This article is 51 days old. Some details may have changed since publication.

Computer Weekly·3 min read·hard

US cyber agency warns over forgotten SharePoint flaw

A
Alex Scroxton
US cyber agency warns over forgotten SharePoint flaw
AI Summary

CISA has added a critical remote code execution flaw in Microsoft SharePoint to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Organizations are urged to verify their patch levels, as the vulnerability was inadvertently omitted from previous update bulletins.

Why it matters

The oversight in the patch bulletin creates a significant security risk for organizations that rely on automated updates or standard documentation, potentially leaving systems exposed to attackers.

Dive DeeperCreate a free account to unlock

A recently-identified but accidentally unpublicised remote code execution (RCE) flaw in Microsoft SharePoint, tracked as CVE-2026-45659 , has been added to the US Cybersecurity and Infrastructure Security Agency’s (Cisa’s) Known Exploited Vulnerabilities (Kev) catalogue after evidence of active exploitation in the wild was identified.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
Political Bias
Center
LeftLean LCenterLean RRight
Confidence: 90%

The article provides technical, factual information regarding cybersecurity risks and vendor updates.

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in