logo

Act Now: CISA Flags Active Exploitation of Microsoft SharePoint Vulnerability

ID: dfac1ebd-69d2-5054-a632-dfa65a4fa3cf

STIX ID: report--dfac1ebd-69d2-5054-a632-dfa65a4fa3cf

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-01-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added a critical Microsoft SharePoint vulnerability (CVE-2023-29357, CVSS 9.8) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; the flaw allows privilege escalation via spoofed JWT tokens and was demonstrated in an exploit chain combined with CVE-2023-24955. Microsoft issued patches in May/June 2023 and organizations — especially federal agencies — were advised to apply updates by January 31, 2024 to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.