CTIPilot

Microsoft SharePoint

product · product:microsoft-sharepoint single-sourcesingle-source-victim

Also known as: SharePoint, SharePoint Server

Coverage timeline
7
first 2026-07-02 → last 2026-08-06
Peak priority
high
5 high · 2 notable
Sources cited
38
22 hosts
Sections touched
3
active-threats, deep-dive, trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
35
pinned v19.2 · see below

ATT&CK techniques

35 techniques observed across 7 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1598Phishing for Information×1

Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Phishing for information is different from Phishing in that the objective is gathering data from the victim rather than executing malicious code.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1598.004Phishing for Information: Spearphishing Voice×1

Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1190Exploit Public-Facing Application×5

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-06/canton-graubuenden-sharepoint-server-breach · 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · 2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des · ATT&CK page ↗

T1566.001Phishing: Spearphishing Attachment×1

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×2

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×2

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×2

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · 2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×2

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1211Exploitation for Stealth×1

Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.

Evidence: 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

T1564.008Hide Artifacts: Email Hiding Rules×1

Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails. Rules may be created or modified within email clients or through external features such as the <code>New-InboxRule</code> or <code>Set-InboxRule</code> PowerShell cmdlets on Windows systems.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Defense Impairment TA0112

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

Credential Access TA0006

T1003.003OS Credential Dumping: NTDS×1

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1111Multi-Factor Authentication Interception×1

Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1528Steal Application Access Token×1

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1552.004Unsecured Credentials: Private Keys×1

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

Evidence: 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1606Forge Web Credentials×1

Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies, tokens, or other materials to authenticate and authorize user access.

Evidence: 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

T1621Multi-Factor Authentication Request Generation×1

Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Discovery TA0007

T1087.002Account Discovery: Domain Account×1

Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.

Evidence: 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1021.006Remote Services: Windows Remote Management×1

Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1534Internal Spearphishing×1

After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user. Adversaries may then attempt to take advantage of the trusted internal account to increase the likelihood of tricking more victims into falling for phish attempts, often incorporating Impersonation.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · ATT&CK page ↗

Collection TA0009

T1213.002Data from Information Repositories: Sharepoint×2

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1102Web Service×1

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-08-06/canton-graubuenden-sharepoint-server-breach · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗

Story timeline

  1. 2026-08-06Canton Graubünden discloses a SharePoint server breach a day after the Confederation did; the on-premises wave has reached Swiss cantonal government
    active-threatsA second Swiss public-sector SharePoint victim in 48 hours, and the intrusion sat unnoticed for a week
  2. 2026-08-05Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed
    deep-diveSwiss federal SharePoint servers breached mid-patching, ~200 accounts taken, servers now being rebuilt
  3. 2026-07-29Talos IR Trends Q2 2026: ransomware operators ran their command-and-control through legitimate RMM agents, authentication abuse hit two-thirds of engagements, and missing logs stopped root-cause determination outright
    deep-diveCisco Talos IR's quarterly report puts three named intrusion chains on record, led by Sinobi running its command-and-control through a trojanized MeshAgent
  4. 2026-07-18Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
    active-threatsAbbott confirms unauthorized access to its Cancer Diagnostics (Exact Sciences) systems as ShinyHunters claims a helpdesk-vishing to Entra SSO breach
  5. 2026-07-14Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)
    trending-vulnerabilitiesMicrosoft patches two exploited zero-days on-prem: an AD FS privilege escalation and an unauthenticated SharePoint EoP, both KEV-listed same day
  6. 2026-07-10'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
    active-threatsReliaQuest: new 'Helix' extortion cluster (BlackFile/ShinyHunters lineage) vishes staff into device-code sign-ins, then bulk-loots SharePoint
  7. 2026-07-02CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed
    trending-vulnerabilities

Where this entity is cited

  • active-threats3
  • trending-vulnerabilities2
  • deep-dive2

Source distribution

  • msrc.microsoft.com8 (21%)
  • bleepingcomputer.com7 (18%)
  • rapid7.com3 (8%)
  • cisa.gov2 (5%)
  • abbott.com1 (3%)
  • admin.ch1 (3%)
  • advisories.ncsc.nl1 (3%)
  • api.first.org1 (3%)
  • other14 (37%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (38)

Entries about Microsoft SharePoint (7)

2026-07-14 · view entry permalink →

HIGHCVE-2026-56155 +6exploitedupdatedNATOA1

Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)

Microsoft's July 2026 Patch Tuesday is its largest ever by CVE count and carries two zero-days Microsoft confirms were exploited before a fix existed, both added to CISA's Known Exploited Vulnerabilities catalog the same day (BleepingComputer, 2026-07-14). CVE-2026-56155 (CVSS 7.8, CWE-1220) is a local elevation-of-privilege in Active Directory Federation Services: an attacker who already holds a low-privileged authorized session on the AD FS host escalates to administrator (Microsoft MSRC, 2026-07-14). It is a post-foothold escalation rather than an initial-access vector, and Microsoft's advisory credits its own DART incident-response team in the acknowledgements, meaning it surfaced during a live intrusion, so an exposed AD FS host should be treated as a candidate for compromise assessment, not merely patched (Microsoft MSRC, 2026-07-14). CVE-2026-56164 (CVSS 5.3, CWE-306) is the more exposed of the two: a missing-authentication flaw in on-prem SharePoint Server that lets an unauthenticated attacker elevate privileges over the network with no user interaction (Microsoft MSRC, 2026-07-14). Microsoft's mitigation guidance (enable AMSI on the SharePoint/IIS worker processes with Request Body Scan set to Full) indicates the trigger is a crafted HTTP POST body, the same class of exposure as the CVE-2026-45659 SharePoint deserialization RCE reported on 2026-07-02, so operators who already tuned AMSI for that flaw have partial coverage.

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Microsoft MSRC 2026-07-14

It's a missing-authentication flaw, meaning an unauthenticated attacker can hit it over the network with no user interaction required. When something this reachable is being actively abused, patch it now and worry about the score later.

Zero Day Initiative (Trend Micro) 2026-07-14

Patching CVE-2026-55040 will successfully break this exploit chain; this underscores the importance of patching vulnerabilities such as authentication bypasses, which can break complex and high-impact exploit chains.

Rapid7 Labs

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

Microsoft MSRC 2026-07-14

CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances.

CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026.

CISA 2026-07-16

Volgens watchTowr is er een publieke exploit code voor SharePoint kwetsbaarheid CVE-2026-50522 gepubliceerd en wordt deze op on-premise versies van SharePoint nu ook actief misbruikt. Kwaadwillenden kunnen deze kwetsbaarheid misbruiken om zichzelf voor langere termijn toegang tot netwerken van kwetsbare systemen te verschaffen, door middel van het stelen van machine-keys.

NCSC-NL (advisory NCSC-2026-0237)

Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.

BleepingComputer (relaying watchTowr) 2026-07-21

allows a remote attacker to execute code over a network without authentication

BleepingComputer 2026-07-14

this vulnerability is the second in a pair of exploits which, when chained together, comprise a critical unauthenticated remote code execution vulnerability in a vulnerable SharePoint server

Alongside today’s coordinated disclosure of CVE-2026-63520, Rapid7 has now published a detailed technical analysis and proof-of-concept for CVE-2026-55040, the first vulnerability in the chain.

Rapid7 2026-08-11

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Microsoft Security Response Center 2026-08-11

The root cause is a chain of four distinct weaknesses that, when combined, allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user.

This single line disables the JWT library's cryptographic signature verification.

Rapid7 2026-08-11

Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots

Defused, quoted by BleepingComputer

Internet threat watchdog Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online.

While Microsoft has labeled this security flaw as an attractive target for attackers

BleepingComputer 2026-07-14

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

CISA Known Exploited Vulnerabilities catalog

The authentication feature could be bypassed as this vulnerability allows impersonation.

Microsoft Security Response Center 2026-08-11
Updaterun 2026-07-15T0409Z-intelactionsaffected_productscvesevidencesourcestagstechniquesbody

The July Patch Tuesday entry covered the two KEV-listed exploited zero-days (AD FS CVE-2026-56155, SharePoint CVE-2026-56164). Four further high-severity fixes in the same cycle carry pre-auth risk and warrant separate attention. CVE-2026-55040 (CVSS 9.1, weak authentication) is a SharePoint JWT token-validation bypass that Rapid7's Stephen Fewer built into a two-vulnerability chain for Pwn2Own Berlin 2026: a remote unauthenticated attacker who knows a target's Active Directory SID or User Principal Name can forge identity and operate as that SharePoint user or administrator (Rapid7 Labs, 2026-07-14). Rapid7 chained it to a still-undisclosed RCE that Microsoft will not patch until the August 2026 cycle, but "patching CVE-2026-55040 will successfully break this exploit chain," so the July update is the available defense today even with the RCE half outstanding (Rapid7 Labs, 2026-07-14).

CVE-2026-55944 (CVSS 9.8) is an unauthenticated deserialization RCE in Microsoft Dynamics NAV / Dynamics 365 Business Central (on-premises), "deserialization of untrusted data ... allows an unauthorized attacker to execute code over a network," triggered by a crafted login request before any session exists (vector AV:N/AC:L/PR:N/UI:N), and rated "Exploitation More Likely" (Microsoft MSRC, 2026-07-14). It is easy to overlook against SharePoint or Exchange in a busy Patch Tuesday, yet on-prem Dynamics back-office instances are frequently exposed. Two more SharePoint deserialization RCEs, CVE-2026-50522 and CVE-2026-58644 (both CVSS 9.8, "Exploitation More Likely"), require Site-Owner-level access per Microsoft's FAQ; CVE-2026-50522 is fixed in the July cumulative update, while CVE-2026-58644's patch actually shipped in the June cumulative update and the CVE was only documented on 14 July after being omitted from June's release notes, so a SharePoint estate patched through June is already covered for 58644 (Microsoft MSRC, 2026-07-14).

Updaterun 2026-07-17T0409Z-intelactionscvesevidencesourcestechniquesbody

The 2026-07-15 entry carried CVE-2026-58644 as a CVSS 9.8 SharePoint deserialization RCE rated only "Exploitation More Likely," with its patch noted as having shipped in the June 2026 cumulative update. CISA has now confirmed it is being exploited in the wild: its SharePoint alert, updated 2026-07-16, states CISA "is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances," and CISA added CVE-2026-58644 to the KEV catalog the same day (CISA, 2026-07-16). The alert describes the cluster's post-exploitation as stealing IIS machine keys (the ASP.NET view-state signing/encryption keys) and using deserialization techniques to gain persistence and deploy malware, so the machine key, not the single CVE, is the durable foothold once any of the four is exploited.

Updaterun 2026-07-22T0409Z-intelcvesevidenceregionssourcestagsbody

The July 2026 SharePoint patch cluster carried CVE-2026-50522, a deserialization-of-untrusted-data RCE that all sources had assessed as not-yet-exploited (Microsoft flagged only an "increased likelihood"). That changed on 2026-07-21: NCSC-NL updated advisory NCSC-2026-0237 to report, per watchTowr, that public exploit code for CVE-2026-50522 was published and the flaw is now actively exploited against on-premises SharePoint, with attackers stealing machine keys for long-term access (NCSC-NL, 2026-07-21).

watchTowr detailed the chain (relayed via BleepingComputer): a malicious .NET BinaryFormatter payload is delivered as the cookie of a forged SecurityContextToken in a WS-Federation sign-in response posted to SharePoint's /_trust/default.aspx endpoint; a successfully processed payload executes code and lets the attacker exfiltrate the server's machine keys, which are then used to forge valid ASP.NET authentication tokens/ViewState, giving persistent, re-authenticatable access that survives patching unless the keys are rotated (BleepingComputer, 2026-07-21). A PowerShell PoC (attributed by BleepingComputer to researcher "Janggggg") went public on 2026-07-20, and watchTowr's Attacker Eye honeypots captured successful compromises within hours (BleepingComputer, 2026-07-21); Security Affairs corroborates that the public PoC triggered active exploitation (Security Affairs, 2026-07-21). No authentication is required for the initial RCE.

Updaterun 2026-08-12T0411Z-intelactionscvesevidencereferencesregionssectorssourcestechniquesbody

The entry on July's SharePoint pre-auth JWT bypass covered CVE-2026-55040 as one half of a Pwn2Own chain whose second half was still unpatched, and the W29 outlook carried it as an item in motion, a SharePoint chain half-patched until August. Both halves are now disclosed and one of them has public exploit code. Microsoft's August Patch Tuesday published CVE-2026-63520, a remote code execution vulnerability in SharePoint Server, and Rapid7 (whose Senior Principal Security Researcher Stephen Fewer discovered it) states that "this vulnerability is the second in a pair of exploits which, when chained together, comprise a critical unauthenticated remote code execution vulnerability in a vulnerable SharePoint server" (Rapid7, 2026-08-11). The same post records the second half of the release: "Alongside today's coordinated disclosure of CVE-2026-63520, Rapid7 has now published a detailed technical analysis and proof-of-concept for CVE-2026-55040, the first vulnerability in the chain."

The two records read very differently on their own, which is the point of reading them together. Microsoft classes CVE-2026-63520 as improper input validation (CWE-20), CVSS 8.1 with high attack complexity, severity Important, allowing an unauthorised attacker to execute code over a network (MSRC, 2026-08-11). CVE-2026-55040 is the more severe of the pair on its own terms: "Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network", CWE-1390, CVSS 9.1 with low attack complexity and no privileges or user interaction required, severity Critical (MSRC, 2026-08-11). Microsoft records both as not exploited and not publicly disclosed before their patches, and rates both "Exploitation More Likely". Patches exist for SharePoint Server Subscription Edition, 2019 and 2016 (Rapid7, 2026-08-11).

What moves this ahead of the ordinary patch cycle is not a score but the disclosure state. The authentication-bypass half now has published analysis and working proof-of-concept code, and the code-execution half it chains into was documented the same day, so the research cost of reconstructing an unauthenticated RCE against an unpatched on-premises farm has collapsed to reading two public write-ups. Nothing in either advisory reports exploitation yet; the exposure is the window between publication and patch coverage, on a product class whose internet-facing deployments are collaboration portals rather than obscure infrastructure.

That window matters more than usual for this constituency. Two Swiss public-sector SharePoint compromises were disclosed in the last nine days, the Confederation's own IT provider on 4 August and the canton of Graubünden on 5 August, both on-premises estates and both attributed by the affected bodies to the SharePoint flaws disclosed in mid-July. Neither of those intrusions involves the CVEs here, and nothing in the cited sources connects them; the relevance is the estate, not the incident. An organisation that has just rebuilt or re-imaged SharePoint servers in response to the July wave is exactly the organisation whose new builds may predate both the July and August updates, and whose asset inventory for those hosts is least likely to be current.

Detection concepts are constrained by what has been published: neither Microsoft record describes the vulnerable code path, and this entry does not have Rapid7's technical analysis in hand, so behavioural detail beyond the advisories would be invention. What the advisories do support is exposure work rather than detection work, enumerate on-premises SharePoint farms and their patch levels across Subscription Edition, 2019 and 2016, and treat internet-reachable ones as the priority, since both halves of the chain are network-reachable with no authentication and no user interaction. Where a farm's August update cannot be applied immediately, restricting the server's reachability to authenticated internal networks is the control that does not depend on knowing which request shape to look for.

Updaterun 2026-08-13T0412Z-intelactionsaffected_productscvesentitiesevidencesourcestechniquesbody

Yesterday's entry recorded that Rapid7 had published a technical analysis and proof-of-concept for CVE-2026-55040 and stated plainly that it did not have that analysis in hand, so no behavioural detail could be offered. Two things changed within a day. The proof-of-concept is being used in attacks, and the analysis (read in full for this entry) turns an exposure problem into a hunt.

Threat-intelligence company Defused reported on 2026-08-12 that "Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots", roughly a day after the code was published (BleepingComputer, 2026-08-12). That is one company observing its own sensors, not a vendor confirmation: the same report notes that "While Microsoft has labeled this security flaw as an attractive target for attackers", it has not yet flagged it as successfully exploited in the wild (BleepingComputer, 2026-08-12). Switzerland's NCSC added the exploitation-attempt claim to its own July Patch Tuesday advisory on 12 August, having added the analysis and proof-of-concept to the same advisory the day before (NCSC-CH, 2026-08-12). For scale, the same reporting cites Shadowserver, which "currently tracks over 8,500 Microsoft SharePoint servers exposed online", with the honest caveat that how many are honeypots or already patched is unknown (BleepingComputer, 2026-08-12).

How the bypass works, and why it matters that it is four bugs and not one. Rapid7's analysis, based on decompilation of the identity module from a fully patched Subscription Edition build, states that "The root cause is a chain of four distinct weaknesses that, when combined, allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user" (Rapid7, 2026-08-11). SharePoint's server-to-server authentication uses a nested token: an outer token carrying user identity claims, and an inner "actor token" representing the calling application that is expected to be cryptographically signed. Each of the four failures removes one guarantee from that design.

First, the token handler explicitly turns off the requirement for signed tokens when it builds its validation parameters; Rapid7's description is blunt: "This single line disables the JWT library's cryptographic signature verification", so the outer token is accepted with no signature at all. Second, the code resolves the inner actor token's signing key from a thumbprint value carried in that token's own header, searching all trusted certificates including SharePoint's own local security-token-service certificate, and assigns the resolved key without ever verifying a signature against it. Third, issuer validation then looks for a registered token service matching that certificate, does not find one (because the server's own signing certificate is not in the collection being searched) and treats the absence of a match as grounds to accept rather than reject. Fourth, the final signature step requires only that a signature string be non-empty; any arbitrary value satisfies it. The result is that the identity in the outer token's name claim, which the caller chooses, is resolved to a real account. (Rapid7, 2026-08-11)

Two properties of that chain matter operationally more than the mechanics themselves. The certificate whose thumbprint the attacker needs is published by the server: Rapid7 records that it is retrievable from an unauthenticated metadata endpoint on the SharePoint site itself, so no prior access is required to obtain it. And picking a useful identity is a separate reconnaissance step, Rapid7 describes querying the target's domain controller over an anonymous SMB session to learn the domain identifier, then walking relative identifiers to enumerate candidate accounts and find one that is a site administrator, noting that a user principal name works too but is less reliable to guess. (Rapid7, 2026-08-11)

Detection, in telemetry terms. The decisive weakness leaves a server-side record: Rapid7's decompilation shows the issuer-validation path emitting a trace message stating that the issuer was accepted because no registered token service matches the signing certificate, immediately before returning success (Rapid7, 2026-08-11). On a healthy farm that path should be rare; on an attacked one it fires on every forged token. That message in the SharePoint diagnostic trace logs is the highest-value single artefact available, and it is a server-side one, so it survives an attacker who never touches the endpoint. Alongside it, three sequences are worth building around: an unauthenticated request to the site's metadata endpoint from an external address, followed within a short window by bearer-token requests to the site's REST API from the same source; authenticated REST activity (reading files, minting a form digest, changing configuration) with no corresponding interactive sign-in or federation token issuance for that account in identity logs; and anonymous SMB sessions enumerating account identifiers from an address that also talks to the SharePoint front end.

Triage: legitimate server-to-server integrations also present bearer tokens to the SharePoint REST API, which is why the token's presence is not the signal. The discriminators are the ones the mechanism forces: a token whose acceptance is accompanied by the unregistered-signing-certificate trace message, activity attributed to a highly privileged account with no matching sign-in event in the identity provider, and an external source address that fetched the unauthenticated metadata endpoint shortly beforehand. A normal integration is registered, so its issuer resolves against a registered token service and never takes the accepting-by-default branch.

Updaterun 2026-08-19T0410Z-intelactionscvesevidencesectorssourcestechniquesbody

The exploitation status flipped. CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog on 2026-08-18, describing it as a weak-authentication flaw that "allows an unauthorized attacker to bypass a security feature over a network" (CISA KEV catalog, 2026-08-18), ENISA's EU Vulnerability Database carries the same date and an EPSS probability of 0.0397 (which EUVD renders as the percentage 3.97), mirroring that determination rather than independently confirming it (ENISA EUVD, 2026-08-18). The earlier entry carried this flaw as proof-of-concept-public on the strength of Rapid7's exploit being replayed against honeypots a day after publication, real exploitation attempts, but against sensors rather than estates. The federal catalogue now classes it as exploited outright, which is a stronger statement than honeypot telemetry even though it rests on one authority.

Microsoft's own record has not moved. It still records exploitation as no, and its published explanation of the impact remains that "the authentication feature could be bypassed as this vulnerability allows impersonation" (Microsoft Security Response Center, 2026-07-14) (the vendor rates the flaw Critical at CVSS 9.1 and does assess exploitation as more likely, which agrees with the catalogue's direction) what disagrees is the record's own exploited field, still set to no with no revision since 14 July. That is the second Microsoft CVE in this catalogue update whose exploited field contradicts the catalogue, and it is a reason not to let a vendor-scored feed be the only input to a SharePoint patch decision. (On the sibling IKE Extension flaw the vendor's exploitability assessment is the disagreeing field too; here only the exploited flag is.)

The reason this matters here more than the score suggests is the estate. Switzerland's federal IT provider BIT confirmed a SharePoint Server intrusion affecting around 200 federal user and technical accounts, and canton Graubünden disclosed its own SharePoint server breach a day later, both already covered here, and neither publicly tied to this identifier by any source. What the exploitation listing changes is the standing of an unpatched, internet-reachable farm: the honest reading is no longer "a proof-of-concept exists" but "this is being used", and a farm that sat exposed between the July patch and now warrants a look at its authentication records rather than an upgrade ticket alone.

Hunting concentrates on the impersonation outcome rather than the request that produced it, because a forged token is accepted by design once validation fails. In authentication and application telemetry, the signals are SharePoint access events whose asserted identity has no corresponding interactive sign-in from the same source within the session window, site-administrator-level operations from a client that never authenticated normally, and unauthenticated requests to token-handling endpoints immediately preceding privileged activity. Triage: federated and app-only access legitimately produce SharePoint operations with no interactive sign-in, so that pattern alone is normal in most tenants; the discriminators are whether the asserted principal is one that federation or a registered application is actually configured to assert, and whether the source address belongs to the estate's own service ranges. Patching is the remediation; there is no configuration workaround in the vendor's record.

Correctionrun 2026-09-06T1308Z-auditcvesbodyactions

The EPSS figure quoted for CVE-2026-55040 in the update of 19 August was ENISA's EU Vulnerability Database rendering, which expresses EPSS as a percentage rather than as the probability itself. EUVD's own API returns the value multiplied by one hundred, so the 3.97 recorded there is an exploitation probability of 0.0397, not 3.97 (FIRST.org EPSS API, value as of 2026-08-18). Nothing about the exploitation assessment changes: CISA's catalogue listing, not the EPSS figure, is what moved this flaw to exploited.

The action list is also cut back. It had grown to eight items across four updates, five of them restating the same SharePoint patch step at four different build baselines, and two months on most of those baselines are superseded. What remains are the three tasks still worth starting now: bringing every on-premises SharePoint farm to the August 2026 build and every AD FS server to the July cumulative update, with a compromise assessment for any farm that was internet-reachable while unpatched; hunting and evicting machine-key harvesters before rotating IIS machine keys; and searching server-side trace logs back to 2026-08-11 for the issuer-validation message that distinguishes a forged token from a normal one.

vulnerability14 Jul 20:19Zmulti-sourceOpen finding ↗

2026-07-02 · view entry permalink →

HIGHCVE-2026-45659exploitedupdated

CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 (CISA KEV feed, 2026-07-01), the operationally significant signal here, because it is the first public confirmation that this deserialization path is under active exploitation. The flaw (CWE-502, deserialization of untrusted data, CVSS 8.8) lets an attacker holding a minimum of Site Member permissions execute code on the SharePoint Server backend with no further user interaction (Microsoft MSRC). It affects SharePoint Server Subscription Edition, 2019 and Enterprise Server 2016, and Microsoft shipped the fix on 2026-05-21 (Microsoft MSRC); the CVE having initially been omitted from the May 2026 Security Updates before publication, per Help Net Security's coverage (Help Net Security, 2026-05-26). Notably, Microsoft's own advisory still rates the CVE "Exploitation Less Likely"; a contradiction defenders should resolve in favour of the exploitation evidence. On-prem operators who deferred the May update because of that low rating should apply it now; hunt SharePoint/IIS logs for anomalous POST bodies to the SharePoint object-model / API endpoints from low-privileged Site-Member sessions followed by unexpected w3wp.exe child-process spawns (T1190, with T1505.003-style web-shell follow-on typical of prior SharePoint deserialization waves).

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 (CISA KEV feed, 2026-07-01), the operationally significant signal here, because it is the first public confirmation that this deserialization path is under active exploitation.

ctipilot v2 brief (migrated)

On Tuesday, CISA also confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs.

BleepingComputer 2026-08-12

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

CISA Known Exploited Vulnerabilities catalog
Updaterun 2026-08-13T0412Z-intelaffected_productscvesevidenceregionssectorssourcestagstechniquesbody

The original entry recorded CISA's 1 July catalogue addition for CVE-2026-45659 as the first public confirmation that this SharePoint deserialization path was being exploited, against a Microsoft advisory that still rated it "Exploitation Less Likely". The catalogue entry has since gained a second flag.

Queried directly this run, the Known Exploited Vulnerabilities catalog at version 2026.08.11 records CVE-2026-45659 with its ransomware-campaign-use field set to "Known" (CISA KEV catalog, 2026-08-11). That the value changed on 11 August, rather than having been present since the July addition, is reported separately: CISA "confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs" (BleepingComputer, 2026-08-12). The same reporting notes that of the fourteen SharePoint vulnerabilities the agency has flagged as actively exploited since November 2021, eight have also been exploited in ransomware attacks.

The flaw itself is unchanged from the original coverage: deserialization of untrusted data reachable by an attacker holding at least Site Member permissions, CVSS 8.8, patched by Microsoft on 2026-05-21. No source names the operation responsible, its victims, or how the required authenticated access is obtained in these campaigns, and none is asserted here.

vulnerability02 Jul 04:55Zmulti-sourceOpen finding ↗

2026-08-06 · view entry permalink →

HIGHexploitedNATOA2

Canton Graubünden discloses a SharePoint server breach a day after the Confederation did; the on-premises wave has reached Swiss cantonal government

The Amt für Informatik (AFI) of Canton Graubünden detected a cyberattack against the SharePoint server that hosts the cantonal administration's public web presence (Kanton Graubünden, 2026-08-05). The canton's own account is that a first analysis found no indication that accounts were compromised or data exfiltrated, and that confidential information and specially-protected personal data are not stored on those web-presence servers in the first place; the cantonal ePortal and specialised applications were unaffected and remained reachable through the remediation (Kanton Graubünden, 2026-08-05). AFI head Lorenz Tanner, speaking to the Keystone-SDA news agency, put the intrusion on the afternoon of 29 July and said two files were placed on the server whose code was not executed, meaning the compromise sat unremarked for roughly a week before disclosure (persoenlich.com, 2026-08-05). AFI carried out an extraordinary update from the evening of 5 August (persoenlich.com, 2026-08-05), during which the canton said its website would be unreachable for several hours (Kanton Graubünden, 2026-08-05).

What makes this operationally significant for the constituency is not the canton's own limited damage but the pattern: this is the second confirmed Swiss public-sector victim of on-premises SharePoint exploitation disclosed in two days, after the Confederation's IT provider BIT reported roughly 200 compromised federal user and technical accounts (covered here on 2026-08-05). Tanner's stated view is that it could be the same vulnerability identified at federal level, one he describes as affecting SharePoint systems worldwide, and AFI is coordinating with the Federal Office for Cybersecurity (persoenlich.com, 2026-08-05). That link is a plausibility stated by the victim, not a confirmed technical finding, neither Swiss disclosure names a CVE, and no authority has published one for either incident, so an operator should treat "same flaw as the Confederation" as a working hypothesis rather than a scoping fact.

Triage: SharePoint farms legitimately write files into those directories during solution deployments, patch installation and content updates, so file creation alone is not the signal. The discriminators are timing and actor, writes that fall outside a change window, that are not attributable to an administrator session or a deployment job, and that are performed by the web-server worker process rather than the update or deployment tooling. A file that never executes, as at Graubünden, produces no process-execution event at all, so a detection strategy resting only on child-process spawning would have missed this one.

Das Amt für Informatik hat einen Cyberangriff auf einen SharePoint-Server des Kantons festgestellt.

Eine erste Analyse hat ergeben, dass es keine Anzeichen darauf gibt, dass Konten kompromittiert oder Daten abgeflossen sind.

Kanton Graubünden, Standeskanzlei 2026-08-05

Es wurden zwei Dateien platziert, deren Code allerdings nicht ausgeführt worden sei.

persoenlich.com (Keystone-SDA) 2026-08-05
incident06 Aug 04:11Zsingle-source · victim disclosureOpen finding ↗

Earlier coverage (4)

2026-08-05HIGHexploitedNATOA2Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installedThe Bundesamt für Informatik und Telekommunikation (BIT), which runs the Swiss Confederation's own data centres, disclosed on 2026-08-04 that its on-premises Microsoft SharePoint Servers were compromised by unknown actors, presumably through the SharePoint flaws Microsoft disclosed in mid-July 2026, and that the credentials of roughly 200 accounts (user accounts and technical service accounts) were taken. BIT had begun installing the July updates immediately after release; staff spotted anomalies on 28 July and confirmed credential compromise on 31 July. Passwords were reset, internet access to SharePoint is blocked for non-federal users, and the affected servers are being rebuilt from scratch rather than patched in place.2026-07-18NOTABLEupdatedNATOA3Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ recordsAbbott Laboratories confirmed (2026-07-16) unauthorized access to a limited number of internal systems in its Cancer Diagnostics business (the acquired Exact Sciences unit) only. Separately, the ShinyHunters extortion group claims the intrusion began with a vishing call that compromised a Microsoft Entra ID single-sign-on account, then used it to pull 30M+ records from Entra, ServiceNow, SharePoint, Databricks and Coupa; a claim Abbott has neither confirmed nor attributed. The confirmed incident plus the same vishing-to-cloud-SSO tradecraft this actor uses against SaaS-integrated enterprises makes it relevant to healthcare and any SharePoint/Entra-dependent estate.2026-07-29NOTABLENATOB2Talos IR Trends Q2 2026: ransomware operators ran their command-and-control through legitimate RMM agents, authentication abuse hit two-thirds of engagements, and missing logs stopped root-cause determination outrightCisco Talos Incident Response published its Q2 2026 quarterly report on 2026-07-28. Three named chains carry the operational value: Sinobi ransomware, in Talos IR's first engagement with the group, used a trojanized MeshAgent binary installed as a SYSTEM auto-start service for encrypted-WebSocket C2, held access for about three days, cracked a weak service-account password from ntds.dit, moved by RDP and WinRM, and deployed ransomware across the entire domain through a malicious GPO logon script with rclone staging exfiltration; Warlock (Storm-2603) was seen deploying the Zoho Assist Unattended Agent, a tool Talos had not previously attributed to it; and UAT-11764 runs a QR-code-in-PDF phishing operation that propagates through each compromised mailbox's own contact list. Two findings cut across all of it, authentication abuse appeared in 65% of engagements, and in several cases logging gaps prevented Talos from determining the initial access vector or the scope of exfiltration at all.2026-07-10HIGHNATOB2'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltrationReliaQuest documented a previously unreported data-extortion cluster it calls Helix, assessed as a likely continuation of the BlackFile (UNC6671) and ShinyHunters ecosystems on shared registrar and hosting infrastructure. Operators phone a target impersonating their named manager (spoofed caller-ID), walk them through an Entra ID device-code sign-in that captures a session token without a password and sidesteps Conditional Access, register a new Authenticator within minutes for persistence, then run automated SharePoint enumeration and bulk exfiltration. SharePoint + Entra ID is the default identity/collaboration stack across Swiss and EU public-sector tenants, so the playbook is directly reachable; disabling the device-code flow is the single highest-impact control.