logo

CISA tags Microsoft SharePoint RCE bug as actively exploited

ID: 4673c2a7-f991-5515-b7a9-419e15d7d08b

STIX ID: report--4673c2a7-f991-5515-b7a9-419e15d7d08b

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-03-27

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warns that two SharePoint Server flaws (CVE-2023-24955 code injection and CVE-2023-29357 JWT auth bypass) can be chained to achieve pre-auth remote code execution; public PoCs and demonstrations exist, and both CVEs were added to CISA's Known Exploited Vulnerabilities catalog with mandated federal patching timelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.