// Service

Microsoft 365

Microsoft 365 / Entra ID productivity and identity suite (Outlook, Teams, SharePoint).

// Alerts

Recent threats

ReliaQuest disclosed a Microsoft 365 email security control bypass affecting the RejectDirectSend setting in Exchange Online. Attackers can bypass authentication requirements and spoof internal users by submitting messages with a null SMTP envelope sender (MAIL FROM:<>), enabling convincing spearphishing attacks that appear to originate from internal addresses. The bypass has been observed in active campaigns since September 2025, targeting executives, managers, finance teams, and procurement personnel with lures including payment requests and file-sharing notices.

Microsoft Threat Intelligence disclosed an active human-operated intrusion campaign exploiting Microsoft Teams external collaboration to impersonate IT support and socially engineer remote access. Attackers deploy a Node.js-based JavaScript implant enabling persistent command execution, then conduct Active Directory reconnaissance and lateral movement via WinRM toward domain controllers. The campaign uses legitimate tools to evade detection and can precede ransomware deployment or data theft.

A public proof-of-concept was released on September 1, 2026 for CVE-2026-62911, an authentication-bypass and file-write vulnerability chain in Microsoft Exchange Server affecting versions 2016 CU23, 2019 CU14/CU15, and Subscription Edition. The PoC details exploitation via NTLM relay against the MRSProxy service, enabling pre-authentication remote code execution as SYSTEM. Microsoft released patches in August 2026; organizations must immediately apply fixes and reduce external exposure to Exchange services.

Public exploit code was released for two SharePoint vulnerabilities (CVE-2026-55040 authentication bypass and CVE-2026-63520 RCE) that can be chained for unauthenticated remote code execution. Threat actors have begun probing SharePoint environments following disclosure. Over 8,700 internet-facing SharePoint instances are potentially vulnerable.

CVE-2026-69414 ShieldBreak is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender. A public proof-of-concept was released on August 12, 2026, allowing low-privileged local attackers to escalate to SYSTEM-level privileges. Microsoft assigned the CVE on August 14 but has not released a patch. CISA issued BOD 26-04 with a 14-day remediation deadline. The vulnerability exploits how Defender processes files during cloud-file hydration using the Cloud Filter API.

TWINLOOT, a Python-based implant, runs its entire command-and-control infrastructure through Microsoft 365 services (SharePoint and Teams) and Azure, authenticating via attacker-controlled Azure tenants. The campaign uses SharePoint as a dead drop and Teams TURN servers for reverse tunnels, evading logging in victim Entra ID and defeating signature-based detection.

A threat actor known as 'TheHatman' claims to have stolen millions of employee records from Azure/Entra ID directories of at least nine Fortune 500 companies, including McDonald's (1.7M records), TCS (~800K), Vodafone (~425K), and others. The exposed data includes full names, corporate emails, job titles, manager chains, and Global Administrator account listings, likely obtained through infostealer-compromised credentials. Researchers assess the data as highly credible and note the stolen org charts are ideal for spear-phishing and business email compromise attacks.

Microsoft patched CVE-2026-68820, a critical use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), on August 22, 2026 as part of Patch Tuesday. The flaw enables local privilege escalation to SYSTEM level and was actively exploited in the wild by the Lazarus Group before the patch shipped. The vulnerability poses significant risk to Windows-based Microsoft 365 infrastructure and endpoint security.

Microsoft disclosed CVE-2026-69836, a critical remote code execution vulnerability in Entra ID (Microsoft's cloud-based identity platform), on August 20, 2026. The flaw stems from unsafe deserialization of untrusted data and requires no authentication, enabling unauthenticated attackers to execute arbitrary code. Microsoft confirmed active exploitation in the wild. Since Entra ID is a managed cloud service, Microsoft deployed the fix server-side automatically; no customer patching is required, but security teams should review sign-in logs and access policies for anomalous activity.

CISA added CVE-2026-33824, a critical double-free vulnerability in Microsoft Internet Key Exchange Service Extensions, to its Known Exploited Vulnerabilities catalog on August 18, 2026, after confirming active exploitation. The flaw enables remote code execution on Windows systems with IKE enabled. A mandatory remediation deadline of August 21, 2026, was set for federal agencies under BOD 26-04.

Microsoft SharePoint Server on-premises vulnerability CVE-2026-55040 allows unauthenticated attackers to bypass authentication via forged JSON Web Tokens. The flaw, affecting SharePoint Server Subscription Edition, 2019, and 2016, was confirmed in active exploitation and added to CISA's Known Exploited Vulnerabilities catalog on August 18, 2026. Microsoft issued fixes in July 2026; organizations delaying patching face immediate risk from proof-of-concept exploits now in the wild.

Varonis Threat Labs disclosed CVE-2026-24301 (CoSnitch), three vulnerabilities in Microsoft Copilot Personal allowing silent data exfiltration from connected apps via single-click crafted links. The flaws exploit automatic prompt execution and connected service access to extract mail metadata, calendar details, file information, and conversation history. Microsoft released patches on August 18, 2026; no wild exploitation observed.

Security researcher Nightmare Eclipse disclosed CVE-2026-69414, dubbed "ShieldBreak," a critical zero-day vulnerability in Microsoft Defender that allows attackers to bypass or disable the widely-deployed endpoint protection platform. Microsoft confirmed active exploitation and is working on a patch. The flaw potentially enables attackers to neutralize endpoint detection before deploying payloads, compromising organizations across all industries that rely on Defender as their primary security control.

XM Cyber disclosed a critical exploit chain affecting Microsoft System Center Configuration Manager (SCCM) that enables remote code execution with SYSTEM privileges. An authenticated domain user without SCCM admin rights can exploit CVE-2026-47301 (broken authorization on AdminService chunked upload) combined with signature validation bypass, path traversal (CabSlip), and unsafe DLL loading to achieve code execution on SCCM primary site servers. Microsoft patched CVE-2026-47301 on July 14, 2026, but related flaws remain unpatched until ConfigMgr 2609 (October 2026).

Microsoft SharePoint Server on-premises versions are vulnerable to the ToolShell exploit chain (CVE-2025-53770), which combines authentication bypass and unsafe deserialization to enable unauthenticated remote code execution. Linen Typhoon (APT27), Violet Typhoon (APT31), and Storm-2603 exploited the flaw in the wild beginning July 18, 2025, within days of Microsoft's advisory. The attack requires two HTTP requests with forged headers and malicious payloads. CVSS score is 9.8. SharePoint Online in Microsoft 365 cloud is not affected; patches are available for on-premises Server versions 2016, 2019, and Subscription Edition.

Microsoft patched six Exchange Server vulnerabilities affecting Exchange Server Subscription Edition, 2019, and 2016 via August 2026 Patch Tuesday. CVE-2026-62913 is a critical remote code execution flaw (CVSS 8.8) exploitable over the network without user interaction via heap-based buffer overflow. CVE-2026-62911 (CVSS 8.0) enables authentication bypass and privilege escalation, demonstrated at Pwn2Own Berlin. Additional flaws include DoS, privilege escalation, spoofing, and authorization bypass impacts.

Microsoft patched CVE-2026-62832 (LegacyHive), a Windows User Profile Service zero-day vulnerability disclosed by researcher Nightmare Eclipse after July 2026 Patch Tuesday. The flaw allows non-admin users to modify the classes registry hive and gain code execution when an administrator logs in. The exploit requires additional credentials but poses a privilege escalation risk in shared systems. Detection queries and proof-of-concept code are publicly available.

FBI and CISA disclosed that Gunra ransomware actors are exploiting Fortinet vulnerabilities (CVE-2024-55591, CVE-2025-24472) to gain initial network access, then conducting stealthy lateral movement and large-scale data exfiltration from Microsoft 365 services, particularly OneDrive and SharePoint. The group uses authentication bypass techniques, disables MFA, and operates primarily during off-hours to evade detection. Ransom demands typically start in the tens of millions.

Microsoft disclosed CVE-2026-50522, a critical remote code execution vulnerability in Microsoft SharePoint Server affecting all on-premises versions. The flaw enables arbitrary code execution via deserialization of untrusted data and is actively exploited by state-sponsored APT groups (Linen Typhoon, Violet Typhoon) and ransomware operators (Warlock, LockBit). Attackers deploy webshells, steal credentials, and establish persistent access; public exploit code is available and campaigns have targeted hundreds of organizations globally including US federal agencies.

Security researcher Chaotic Eclipse released a proof-of-concept exploit called ShieldBreak demonstrating a claimed full patch bypass for CVE-2026-50656 (RoguePlanet), a race condition in Microsoft Defender for Windows that enables SYSTEM privilege escalation. The PoC reportedly achieves 100% success rate on Windows 11 25H2 and Windows Server 2025, contradicting Microsoft's July patch claims.

Researchers disclosed an authentication bypass and remote code execution vulnerability chain affecting Microsoft SharePoint Server on-premises. CVE-2026-55040 allows unauthenticated attackers to impersonate arbitrary users via JWT validation bypasses, which can be chained with CVE-2026-63520 (unsafe .NET type instantiation) to achieve code execution as the Windows service account. The vulnerabilities affect SharePoint Server Subscription Edition, 2019, and 2016; exploitation requires knowledge of the target user's Active Directory SID or UPN. Microsoft shipped a July patch addressing CVE-2026-55040; August patches for CVE-2026-63520 were not yet publicly available at time of publication.

Microsoft's August 2026 Patch Tuesday addresses 400+ vulnerabilities including CVE-2026-68820, a Windows Ancillary Function Driver elevation-of-privilege flaw actively exploited by North Korean threat actor Lazarus to deploy FudModule, a kernel-mode rootkit. Check Point disclosed the zero-day exploitation campaign. Two additional publicly disclosed zero-days (CVE-2026-62832 and CVE-2026-72971) were also fixed. Among critical flaws are remote code execution vulnerabilities in SharePoint (CVE-2026-65665), Windows DHCP (CVE-2026-62823), and Azure services.

CISA confirmed that ransomware gangs are actively exploiting CVE-2026-45659, a high-severity Microsoft SharePoint remote code execution vulnerability. The flaw, tracked since early July, stems from unsafe deserialization and allows low-privilege attackers to execute arbitrary code on unpatched servers with low complexity. CISA added it to the Known Exploited Vulnerabilities Catalog on July 1, 2026, and now reports widespread ransomware abuse.

Security researcher Gareth Heyes disclosed CSS bomb attack techniques affecting multiple webmail services including Outlook. The attacks exploit HTML and CSS sanitization discrepancies to manipulate user interfaces, leak authentication tokens, and capture passwords. Some Outlook-specific vulnerabilities including UI manipulation and interface spoofing were noted as unresolved at publication time, though other services addressed reported issues.

UNC6671, operating under aliases Redact, Pink, Falcon, and Helix, conducted a sustained phishing campaign targeting over 200 financial services firms and enterprises. Attackers posed as IT help desk staff via phone calls to employees' personal numbers, directing victims to fake credential-harvesting websites mimicking company SSO portals to steal usernames, passwords, and MFA codes. Once compromised, attackers deleted security alerts and password reset notifications to hide their presence. Targets included major firms such as Blackstone, Bridgewater Associates, Apollo Global Management, KKR, and CME Group.

Kali365, a phishing-as-a-service platform, is conducting a sustained campaign targeting US companies with device code phishing attacks against Microsoft 365 accounts. The attack abuses Microsoft's legitimate OAuth authentication flow to obtain access and refresh tokens without directly stealing passwords, enabling attackers to compromise corporate email, documents, and cloud services. Threat intelligence shows over 80 phishing sessions per week targeting US organizations across manufacturing, technology, healthcare, government, consulting, and managed service provider sectors.

Switzerland's Federal IT Agency (FOITT) disclosed a compromise of approximately 200 user and technical accounts on on-premises SharePoint servers. Attackers exploited SharePoint vulnerabilities, likely CVE-2026-50522 (CVSS 9.8), disclosed in Microsoft's July 2026 Patch Tuesday. The breach was detected July 28, 2026, and confirmed July 31. FOITT has reset compromised credentials, blocked external SharePoint access, and is rebuilding affected servers with support from Swiss national cybersecurity authorities.

Police National Legal Database (PNLD) data breach exposed police, government, and customer contact details via misconfigured Microsoft Power Pages portals with unauthenticated Dataverse access. ExfilSquad published approximately 108,429 user records on the dark web. The breach, discovered July 26, 2026, likely exploited Power Pages with broad Anonymous Users access to Dataverse tables, exposing names, email addresses, and organizational affiliations of UK law enforcement and justice professionals.