News
Cyber News: SharePoint Attacked Hours After Exploit
This fortnight is a lesson in how fast a patched flaw becomes an emergency once someone publishes working code for it. A SharePoint bug that Microsoft fixed in July sat almost untouched for a month, then went from four exploitation attempts to eight in forty eight hours. Two other actively exploited flaws joined the same catalogue on 18 August.
SharePoint servers attacked within hours of a public exploit
CVE-2026-55040 is an authentication bypass in on-premises SharePoint, rated CVSS 9.1. It lets an unauthenticated attacker forge a valid JWT and impersonate any user on the site, including an administrator, with no credentials, no prior access and no user interaction. Microsoft fixed it in the July Patch Tuesday release. Between 14 July and 11 August, only four exploitation attempts were recorded. Then on 11 August Rapid7 published its technical analysis and a proof of concept script, and attackers began hitting unpatched servers within hours, with eight attempts inside the next two days. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 18 August and set federal agencies a remediation date of 21 August.
The uncomfortable part for a UK business is that this affects SharePoint Server 2016, 2019 and Subscription Edition, the on-premises product, not Microsoft 365. On-premises SharePoint tends to be the box nobody has looked at in a while, often holding contracts, HR files and finance records. Successful exploitation means file disclosure and data modification across the whole farm, which is a reportable personal data breach in most configurations. If you run one, the question is not whether the July updates were approved but whether they are installed, and a compromise before patching would not be undone by patching now. Cyber Essentials requires high and critical patches inside 14 days, and our patch deadline calculator turns a release date into the actual deadline. The write-up is at Rapid7 and the exploitation detail at SecurityWeek.
A macOS flaw is being used to plant cryptocurrency miners
Check Point’s threat intelligence report on 17 August flagged CVE-2026-65400, a macOS Screen Sharing vulnerability rated CVSS 9.8 that allows unauthenticated network access. It is being actively exploited to deploy cryptocurrency miners. Apple has patched it, and CISA added it to the same 18 August catalogue update.
Two things are worth saying about this. First, mining malware is often dismissed as a nuisance rather than a breach, and that is the wrong read: whoever can drop a miner on a machine can drop anything else on it, and the miner is simply the payload they chose to monetise first. Second, a lot of small UK firms treat Macs as the devices that do not need managing, so they sit outside the patch process and outside endpoint monitoring entirely. If your answer to “how many Macs are on your network and are they current?” is a guess, that is the finding. Our endpoint security management guide covers what coverage should actually look like, and the cyber security checklist for businesses is the shorter version. The report is at Check Point Research.
Two more join the actively exploited list, including VMware vCenter
The 18 August catalogue update added four vulnerabilities in total. Alongside the SharePoint and macOS flaws are CVE-2026-59310, a path traversal vulnerability in Broadcom VMware vCenter, and CVE-2026-33824, a double free in the Microsoft Internet Key Exchange service extensions. Check Point’s report also notes CVE-2026-71362, an authentication flaw in Adobe Commerce that attackers used for account takeover shortly after disclosure, and three critical Zoom vulnerabilities including CVE-2026-53413, which could allow remote code execution during a meeting.
The pattern across all of these is the shrinking gap between disclosure and exploitation. The old assumption that you have a comfortable window between a patch being published and anyone bothering to weaponise it no longer holds, and the SharePoint case shows the trigger is often a public write-up rather than the patch itself. That has a practical consequence for insurance: insurers increasingly ask about patch cadence at renewal, and an unpatched internet-facing server with a known exploited flaw is the kind of thing that turns a claim conversation difficult. Our guide to what cyber insurance covers and its exclusions explains where those arguments usually land. The catalogue is at CISA.