Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That.
2026-05-27T08:51:46Z•a2dd83251ed2ef67243a41e121cdb0969fac2132b834b4f9df604b081c31491f
AI-assisted malwareAPTCVE-2026-26980CVE-2026-45659Ghost CMSLaravel-LangLazarusSEO poisoningSharePointStark IndustriesWhatsAppcomposerdata breachexposed databasesfake installersfileless RATgit tag poisoninghosting takedownransomware extortionremote code executionsupply-chainthird-party vendorzero-click
What happened
Multiple high-risk incidents and active campaigns reported: a SharePoint remote code execution vulnerability (CVE-2026-45659, CVSS 8.8) is actively patched — apply updates immediately; Ghost CMS sites continue to be exploited via CVE-2026-26980 with 700+ unpatched sites compromised. Additional supply-chain compromise (Laravel-Lang Git tag poisoning), a memory-only fileless RAT used by Lazarus, AI-assisted malware and fake Zoom installers from Nimbus Manticore, large-scale database extortion activity, a zero-click WhatsApp account takeover affecting iOS 16, and a third‑party patient-data breach
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- a2dd83251ed2ef67243a41e121cdb0969fac2132b834b4f9df604b081c31491f
- Enrichment time
- 2026-05-27T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.