0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Microsoft Office vulnerabilities patched, including actively exploited zero-day in SharePoint (advisories.ncsc.nl)

· 6d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • CVE-2026-58644 is an actively exploited zero-day deserialization vulnerability in SharePoint (CVSS 9.8).
  • Public exploit for CVE-2026-50522 enables remote code execution and machine key theft.
  • Chain of CVE-2026-58644 and CVE-2026-56164 allows unauthenticated remote code execution.

"The Dutch NCSC warns of Microsoft Office patches covering over 80 vulnerabilities. A critical SharePoint deserialization flaw (CVE-2026-58644, CVSS 9.8) is actively exploited as a zero-day. Combined with a privilege escalation bug (CVE-2026-56164, CVSS 5.3), unauthenticated remote code execution is possible. A public exploit for CVE-2026-50522 (CVSS 9.8) is also being used against on-premise SharePoint, allowing attackers to steal machine keys. The NCSC urges immediate updates."

Discussion Matrix

0 segments

no comments yet.