Announcements

Microsoft SharePoint: Microsoft SharePoint Weak Authentication Vulnerability

  • 18th August 2026

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-55040

Continue reading

Broadcom VMware vCenter: Broadcom VMware vCenter Path Traversal Vulnerability

  • 18th August 2026
A security vulnerability has been found in Broadcom's VMware vCenter software. The flaw is a path traversal issue, which means a threat actor with network access to a vCenter instance could run any unapproved code they choose on that system. This level of unauthorized access could let attackers steal sensitive data, alter or delete stored ...
Continue reading

Microsoft Internet Key Exchange (IKE) Service Extensions: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

  • 18th August 2026
A security flaw has been identified in Microsoft’s Internet Key Exchange (IKE) Service Extensions, a component used to set up secure, encrypted connections (including for virtual private network, or VPN, access that many businesses rely on to safely connect to their websites and internal systems). The flaw is a type of memory error called a ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 18th August 2026
On 20 July 2026, cybersecurity response team MyCERT released a public advisory warning of new active exploitation attempts targeting Microsoft SharePoint, a popular platform many organizations use to host shared files, support team collaboration, and share content via their websites.The advisory outlines guidance for hardening SharePoint ...
Continue reading