Skip to finding
important · Edge — SharePoint

Attackers are exploiting a SharePoint SafeControls bypass that turns a low-privilege account into server-side code execution.

Affects

Microsoft SharePoint Server 2016, 2019 and Subscription Edition, on-premises collaboration servers running on Windows.

CISA marked the vulnerability as actively exploited on September 25, and Microsoft has published fixes for supported affected versions.

Detail and 5 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026