decrypted · 19 august 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security

The SharePoint flaw Microsoft patched in July that CISA only just called exploited

Microsoft fixed the SharePoint bypass in July. A researcher published working exploit code on 11 August. This week the US Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalog, the list that forces US federal agencies to patch on a deadline. On-premises SharePoint servers, the sort still running in UK government departments, NHS trusts and any mid-sized organisation that never moved to the cloud edition, are exactly where they were a week ago: facing the internet, and in plenty of cases still unpatched.

What is actually new

We wrote about this flaw, CVE-2026-55040, when Rapid7 published its proof of concept on 11 August. The new development is what has happened since. CISA added the bug to its Known Exploited Vulnerabilities catalog on 18 August, and the tracking service KEVIntel now logs 392 exploitation attempts against it between 19 July and 18 August, from 28 unique attacker IP addresses across eight countries. NHS England had already issued a High Severity Cyber Alert on 12 August warning that this flaw, chained with a second SharePoint bug, allows unauthenticated remote code execution rather than just an authentication bypass. The scale of exploitation, not the existence of the bug, is the story this week.

The Secure by Design lesson

According to Rapid7, the flaw exists because SharePoint's JWT validation pipeline can be tricked into accepting a forged token if an attacker supplies a known user's Active Directory identifier. Think of it as a nightclub door where the bouncer checks your name against a guest list you handed him yourself. Microsoft patched the authentication bypass in July and a related remote code execution component in August, so the fix has existed for weeks. What has not existed is universal patching. That is the recurring Secure by Design failure in on-premises software: a vendor can ship a fix, but every server operator has to apply it individually, and internet-facing management interfaces sit exposed until someone does. UK organisations still running on-premises SharePoint should treat a CISA KEV listing as a genuine deadline even though it binds only US federal agencies, and should audit which of their internet-facing servers are running versions predating July's patches.

Also this week

Ransomware gangs are now using a Windows privilege escalation bug CISA flagged five months ago. CVE-2025-60710, a link-following flaw in Windows Task Host that lets a local attacker reach SYSTEM, was patched in November 2025 and added to CISA's exploited list in April. This week CISA updated that same entry to confirm ransomware groups are now using it, though it has not named which ones. It is a reminder that privilege escalation bugs rarely stay theoretical once a criminal group is already inside a network.

Microsoft took eight months to fully patch a one-click Copilot data theft flaw. Varonis Threat Labs reported the bug, since named CoSnitch and tracked as CVE-2026-24301, to Microsoft on 31 December 2025. Researchers found it by asking Copilot itself how a prompt could run without user interaction, and it told them: an undocumented autorun parameter. A single crafted link could run an attacker's prompt inside a victim's logged-in Copilot Personal session, then query connected Gmail, Drive, Calendar or OneDrive accounts and exfiltrate the results through Copilot's own URL-fetch feature. Microsoft shipped a partial fix in February and the full one only on 18 August. Any UK organisation letting staff link personal or work accounts to consumer AI assistants should assume that convenience and blast radius move together.

Sixteen fake RubyGems packages built a fake build process to hide a real credential stealer. Researchers at OpenSourceMalware found the campaign, dubbed StubMaker, on 15 August. The packages, distributed under typosquatted names, generate a dummy Makefile that reports a clean build while the actual theft, targeting saved browser credentials, cryptocurrency wallet seed phrases and Telegram data, runs from the installer hook. When some packages were pulled, the attackers simply republished them under new accounts. Any development team that installs Ruby dependencies without pinning exact versions and verifying publishers is exposed to exactly this trick.

Sources

Not sure your SharePoint estate is patched? Get in touch and we'll help you find out.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.