logo

New Microsoft SharePoint Vulnerability: CISA Issues Warning

ID: 8282f556-078c-5768-ac36-196ab31676fa

STIX ID: report--8282f556-078c-5768-ac36-196ab31676fa

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-12-04

Date Updated: 2026-07-16

...
...

CISA has issued an advisory for CVE-2024-38094, a high-severity deserialization vulnerability in Microsoft SharePoint (CVSSv3.1 7.2) that allows authenticated Site Owner accounts to inject and execute arbitrary code; proof-of-concept code is publicly available and the issue is listed in CISA's KEV catalog, so organizations should apply Microsoft patches and adopt mitigations such as patch management, network segmentation, monitoring, and incident response planning immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.