logo

CISA Adds 9.8 'Critical' Microsoft SharePoint Bug to its KEV Catalog

ID: 7c7db364-228b-562c-822d-92fa509944a3

STIX ID: report--7c7db364-228b-562c-822d-92fa509944a3

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-01-12

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

CISA added CVE-2023-29357—a critical (CVSS 9.8) SharePoint Server 2016/2019 privilege-escalation flaw that permits authentication bypass via spoofed JSON Web Tokens—to its Known Exploited Vulnerabilities catalog; Microsoft released a patch in June, proof-of-concept code is publicly available, and CISA reports active exploitation including use by a ransomware group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.