<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hackers target Microsoft SharePoint RCE chain with PoC exploit]]></title><description><![CDATA[<p dir="auto">Attackers have shifted focus to a chain of two <strong>Microsoft SharePoint</strong> vulnerabilities that, when combined, allow remote code execution on unpatched servers, according to threat intelligence firm <strong>Defused</strong>. The exploitation activity follows the public release of a proof-of-concept (PoC) that demonstrates how the two flaws can be chained together to bypass existing security measures.</p>
<p dir="auto">The first vulnerability in the chain is a deserialization issue that permits an authenticated attacker to trigger arbitrary code execution. The second flaw acts as an authentication bypass, allowing the attacker to reach the vulnerable deserialization endpoint without valid credentials. While Microsoft has released patches for both issues in recent updates, Defused reports that exploitation attempts are actively targeting organizations that have not yet applied the fixes.</p>
<ul>
<li>The attack chain requires initial access to a SharePoint site, but the authentication bypass removes the need for privileged credentials.</li>
<li>Successful exploitation grants the attacker the ability to execute commands in the context of the SharePoint application pool.</li>
<li>Defused observed the PoC being weaponized in the wild shortly after its disclosure, with scans targeting internet-facing SharePoint servers.</li>
</ul>
<p dir="auto">Defused advises administrators to prioritize patching all SharePoint servers immediately, as the exploit chain is now public and actively used. For organizations that cannot patch immediately, they recommend restricting network access to SharePoint services and monitoring for unusual process execution or web shell activity on affected hosts.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Is your organization running any unpatched SharePoint instances, and how are you balancing the patch rollout with potential service downtime?</p>
]]></description><link>https://xploitlk.com/topic/110/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 14:22:39 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/110.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 26 Aug 2026 18:30:32 GMT</pubDate><ttl>60</ttl></channel></rss>