top of page

Security Bulletin

Public·4 members

Jake Geier
Jake Geier

UPDATE: Critical Microsoft SharePoint Server Zero-Days Under Active Exploitation



What:

  • CISA added critical zero-day vulnerabilities targeting Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog

  • CVE-2026-58644 is a deserialization flaw in SharePoint Server (Subscription Edition, 2019, and 2016) that allows remote, authenticated attackers to execute arbitrary code, gain persistence — historically through IIS machine key theft — and establish footholds in enterprise environments

  • CVE-2026-50522 is a critical SharePoint Server deserialization RCE vulnerability with a CVSS score of 9.8; public proof-of-concept exploit code became available shortly after Microsoft's July 2026 emergency patches, contributing to rapid and widespread exploitation

  • CISA added CVE-2026-58644 to the KEV catalog on July 16, 2026, with a remediation deadline of July 19, 2026 for federal agencies


14 Views
Jake Geier
Jake Geier

Russian APT Exploits OWA Zero-Day to Survive Password Resets — CVE-2026-42897


What:

  • Threat group Laundry Bear (aka TA488/Void Blizzard), previously tied to Zimbra zero-day exploitation, is now exploiting an XSS vulnerability in Microsoft Outlook Web Access tracked as CVE-2026-42897 (CVSS 8.1) thehackernews

  • Activity began July 22, 2026, targeting U.S. and European government entities plus telecom, financial, hospitality, and aerospace sectors thehackernews

  • It's a "half-click" exploit — simply viewing the email triggers the compromise, no clicks or attachments needed, using vague lures like supply chain analyses or tourism/gas market updates thehackernewsthehackernews

  • Deploys a new implant called OWAReaper, which runs entirely in the browser inside the OWA reading pane


5 Views
George SuttonGeorge Sutton
George Sutton

Patch Tuesday Special: June 2026

June 18th, 2026


Overview:

Microsoft’s June 9, 2026 Patch Tuesday addressed ~66–67 vulnerabilities (counts vary slightly by tracker methodology), including one publicly disclosed zero-day and ten critical vulnerabilities. While no vulnerabilities were confirmed as actively exploited at release, the presence of a publicly disclosed WebDAV flaw and several critical Remote Code Execution (RCE) vulnerabilities affecting core Windows services makes this a high-priority patch cycle.


Vulnerability Category Breakdown:

• Remote Code Execution (RCE): ~25 vulnerabilities (~37%)


37 Views
George SuttonGeorge Sutton
George Sutton

The New HTTP/2 Bomb DoS Attack: Small Requests, Massive Damage

June 5th, 2026


❓What:

Researchers at offsec firm Calif disclosed a new denial-of-service (DoS) attack dubbed HTTP/2 Bomb that can crash major web servers using a single client system. The attack combines two previously known HTTP/2 weaknesses:

  • HPACK compression amplification; which causes small requests to consume large amounts of server memory.

  • HTTP/2 flow-control abuse; which prevents that memory from being released.


21 Views
bottom of page