Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That.

2026-05-27T08:51:46Za2dd83251ed2ef67243a41e121cdb0969fac2132b834b4f9df604b081c31491f
AI-assisted malwareAPTCVE-2026-26980CVE-2026-45659Ghost CMSLaravel-LangLazarusSEO poisoningSharePointStark IndustriesWhatsAppcomposerdata breachexposed databasesfake installersfileless RATgit tag poisoninghosting takedownransomware extortionremote code executionsupply-chainthird-party vendorzero-click

What happened

Multiple high-risk incidents and active campaigns reported: a SharePoint remote code execution vulnerability (CVE-2026-45659, CVSS 8.8) is actively patched — apply updates immediately; Ghost CMS sites continue to be exploited via CVE-2026-26980 with 700+ unpatched sites compromised. Additional supply-chain compromise (Laravel-Lang Git tag poisoning), a memory-only fileless RAT used by Lazarus, AI-assisted malware and fake Zoom installers from Nimbus Manticore, large-scale database extortion activity, a zero-click WhatsApp account takeover affecting iOS 16, and a third‑party patient-data breach

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a2dd83251ed2ef67243a41e121cdb0969fac2132b834b4f9df604b081c31491f
Enrichment time
2026-05-27T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That. · Baitaphish