BBLabs NewsBBLabs News
NewsAll articlesTopics
ES
BBLabs NewsBBLabs News

BBLabs News

Una historia al día. Cero ruido.

Newsletter técnica de ciberseguridad. Una historia al día sobre CVEs críticos, brechas, bug bounty e IA. Filtrado por IA, escrito para humanos.

Producto

  • Hemeroteca
  • Ediciones
  • Temas
  • Glosario
  • RSS
  • Atom
  • JSON Feed

Editorial

  • Acerca de
  • Suscribirse
  • Cuenta
  • English

Legal

  • Privacidad
  • Términos
  • Contacto: team@bblabs.es

Conectar

  • YouTube · @0xGorka
  • Instagram · @bblabs.es
  • Discord BBLabs
  • Discord Bug Bounty ES
20 artículos·5 ediciones·Desde 2026·Hecho en España
© 2026 BBLabs News·Por Gorka El Bochi
BBLabs NewsBBLabs News
NewsAll articlesTopics
ES
Emergency SharePoint patch: update now
Back to homeCVE

Emergency SharePoint patch: update now

Microsoft issued an out-of-band SharePoint patch, signaling active exploitation or critical severity outside the normal Patch Tuesday cycle.

  1. Home
  2. ›
  3. CVE
  4. ›
  5. Emergency SharePoint patch: update now
by Gorka El Bochi Morillo
·
2 min read
·May 31, 2026

What happened

Microsoft released an out-of-band patch for SharePoint — outside the regular monthly Patch Tuesday cycle. That move has one clear meaning: either there's already documented active in-the-wild exploitation, or the CVSS score (severity rating from 0–10) is high enough that waiting weeks would be indefensible.

Full technical details on the CVE were not completely disclosed at time of writing — consistent with Microsoft's standard practice of limiting exposure before a public PoC (proof-of-concept code that demonstrates the bug is exploitable) surfaces.

SharePoint On-Premises is the most exposed vector. SharePoint Online (Microsoft 365) receives the fix automatically from Microsoft; on-prem deployments require manual admin action.

Why it matters

SharePoint is literally the keys to the kingdom in enterprise environments — not hyperbole. It concentrates financial documents, credentials stored in loose files, approval workflows, and, most critically, deep native integration with Active Directory (AD) (Windows' central identity and permissions directory).

An RCE (remote code execution — attacker runs arbitrary code on the server) on SharePoint opens the door to immediate lateral movement, credential dumping, and in many cases full domain takeover. APT groups (state-sponsored hacker teams) have used SharePoint as a preferred entry point into government organizations and Fortune 500 companies for years.

The out-of-band urgency amplifies everything: if Microsoft couldn't wait until next Tuesday, someone is already exploiting this or is about to.

What to do

  • Patch SharePoint On-Premises today. No exceptions for maintenance windows.
  • Confirm SharePoint Online (M365) reflects the update in the admin portal.
  • Review access logs from the last 72 hours for anomalous requests to `/layouts/`, `/_vti_bin/`, or unauthenticated requests returning 200 responses.
  • If you have a SOC (security operations center — the team that monitors threats), escalate to high priority until you confirm no IOC (technical attacker fingerprints) predate the patch.
  • Block external access to SharePoint On-Premises if not strictly required until patch is confirmed applied.

Microsoft's out-of-band SharePoint patches have a track record of becoming ransomware entry points within 48 hours of publication. The action window is short.

What to do

  • Patch SharePoint On-Premises before anything else today.
  • Check `/layouts/` and `/_vti_bin/` access logs from the last 72 hours for anomalous hits.
  • Block external SharePoint access until patch is confirmed if you run on-prem.

Share this story

Help more people discover BBLabs News.

Emergency SharePoint patch: update now
VerticalDownload image
LinkedInXWhatsApp

Interested in CVE?

Subscribe to this stream and get the most relevant news every day — no spam, no noise.

Subscribe

Related articles

Destacado
CVE26 may 2026·2 min

CVE-2026-31635 DirtyDecrypt: public PoC for Linux kernel LPE

Public PoC released for CVE-2026-31635 (DirtyDecrypt), a Linux kernel local privilege escalation flaw discovered by Zellic and V12.

  • Run `uname -r` and verify your kernel version against the official distro advisory before assuming you're patched.
  • Prioritize kernel updates on CI/CD runners, shared VPS, and any host where untrusted users execute code.
  • Add SIEM rules to flag unexpected UID changes or SUID binary executions linked to CVE-2026-31635.
Gorka El Bochi Morillo
Leer artículo
CVE26 may 2026·2 min

SharePoint RCE CVE-2026-45659 patched — CVSS 8.8

Microsoft patches CVE-2026-45659 in SharePoint Server — RCE via untrusted data deserialization, CVSS 8.8, no special attack conditions required.

Leer artículo
CVE24 may 2026·2 min

CVE-2026-34926: Apex One zero-day actively exploited

CVE-2026-34926, a directory traversal zero-day in TrendAI Apex One on-premise, is being actively exploited in the wild; patch is available.

Leer artículo

Want to get news like this every day?

Browse all articles
BBLabs NewsBBLabs News

BBLabs News

Una historia al día. Cero ruido.

Newsletter técnica de ciberseguridad. Una historia al día sobre CVEs críticos, brechas, bug bounty e IA. Filtrado por IA, escrito para humanos.

Producto

  • Hemeroteca
  • Ediciones
  • Temas
  • Glosario
  • RSS
  • Atom
  • JSON Feed

Editorial

  • Acerca de
  • Suscribirse
  • Cuenta
  • English

Legal

  • Privacidad
  • Términos
  • Contacto: team@bblabs.es

Conectar

  • YouTube · @0xGorka
  • Instagram · @bblabs.es
  • Discord BBLabs
  • Discord Bug Bounty ES
20 artículos·5 ediciones·Desde 2026·Hecho en España
© 2026 BBLabs News·Por Gorka El Bochi