SEKurity GmbH Logo
Home/Tags/Microsoft

#Microsoft

5 Articles tagged

[*] Filtering articles by tag: Microsoft
[+] Matching entries: 5
root@sekurity:~# ls -la /tags/microsoft/* _

CVE Research
sekurity-team

InSEKurity of the Week (CW34/2026): Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)

Four separate failures in SharePoint's JWT validation pipeline let an unauthenticated attacker forge a token for any user -- including a site administrator -- and CISA added it to the KEV catalog on August 18 after exploitation followed the public PoC within a day.

01
CVE Research
sekurity-team

InSEKurity of the Week (CW27/2026): Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659)

A deserialization flaw in Microsoft SharePoint Server lets an authenticated low-privilege user run code on the server -- now added to the CISA KEV catalog under confirmed active exploitation

02
CVE Research
sekurity-team

InSEKurity of the Week (CW22/2026): Windows Netlogon Pre-Auth RCE on Domain Controllers (CVE-2026-41089)

Critical stack-based buffer overflow in Windows Netlogon lets unauthenticated attackers run SYSTEM code on any Windows domain controller over the network -- now under active exploitation

03
CVE Research
sekurity-team

InSEKurity of the Week (CW17/2026): Windows TCP/IP IPv6 + IPsec RCE (CVE-2026-33827)

Critical pre-auth race condition in the Windows TCP/IP stack lets remote attackers run code over IPv6 against any IPsec-enabled host -- wormable, no credentials, no user interaction

04
CVE Research
sekurity-team

InSEKurity of the Week (CW16/2026): Windows IKE Extensions RCE (CVE-2026-33824)

Critical pre-auth double free in the Windows IKE Service Extensions (IKEEXT.dll) lets remote attackers reach SYSTEM over UDP/500 and UDP/4500 -- wormable, public PoC already online

05

root@sekurity:~# echo "End of results for tag: Microsoft"
End of results for tag: Microsoft
root@sekurity:~# _