<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Microsoft SharePoint</title><description>Cybersecurity articles tagged #Microsoft SharePoint on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>SharePoint RCE via CVE-2026-55040 &amp; CVE-2026-63520: Patch Now</title><link>https://runtimerebel.com/blog/sharepoint-rce-via-cve-2026-55040-cve-2026-63520-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/sharepoint-rce-via-cve-2026-55040-cve-2026-63520-patch-now</guid><description>An AI-assisted exploit chain, leveraging CVE-2026-55040 and CVE-2026-63520, enables unauthenticated RCE on Microsoft SharePoint Server. Immediate patching is critical.</description><pubDate>Mon, 17 Aug 2026 00:39:44 GMT</pubDate><category>Microsoft SharePoint</category><category>Remote Code Execution</category><category>Vulnerability Chaining</category><category>AI in Cybersecurity</category><category>CVE-2026-55040</category></item><item><title>CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC</title><link>https://runtimerebel.com/blog/cve-2026-55040-critical-sharepoint-auth-bypass-exploited-after-poc</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-55040-critical-sharepoint-auth-bypass-exploited-after-poc</guid><description>Attackers exploit CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint, leading to data disclosure and modification.</description><pubDate>Thu, 13 Aug 2026 09:02:53 GMT</pubDate><category>Microsoft SharePoint</category><category>Authentication Bypass</category><category>Zero Day Exploitation</category><category>Proof of Concept</category><category>CVE-2026-55040</category></item><item><title>Swiss Government SharePoint Breach: 200 Accounts Compromised</title><link>https://runtimerebel.com/blog/swiss-government-sharepoint-breach-200-accounts-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/swiss-government-sharepoint-breach-200-accounts-compromised</guid><description>Switzerland&apos;s federal IT office confirms a Microsoft SharePoint breach compromised approximately 200 accounts, leading to a swift remediation.</description><pubDate>Mon, 10 Aug 2026 00:59:49 GMT</pubDate><category>SharePoint</category><category>Data Breach</category><category>Swiss Government</category><category>Account Compromise</category><category>Microsoft SharePoint</category></item><item><title>CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</guid><description>CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…</description><pubDate>Sun, 02 Aug 2026 16:49:14 GMT</pubDate><category>CVE-2026-50522</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2023-29357: CISA Warns of Active SharePoint Exploit Chain</title><link>https://runtimerebel.com/blog/cve-2023-29357-cisa-warns-of-active-sharepoint-exploit-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-29357-cisa-warns-of-active-sharepoint-exploit-chain</guid><description>CISA urges immediate patching of CVE-2023-29357 and CVE-2023-24955 in SharePoint Server due to active exploitation for remote code execution.</description><pubDate>Wed, 15 Jul 2026 10:05:47 GMT</pubDate><category>CVE-2023-29357</category><category>CVE-2023-24955</category><category>Microsoft SharePoint</category><category>CISA KEV</category></item><item><title>CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-exploitation-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-exploitation-mitigation-guide</guid><description>CISA adds CVE-2026-45659, a high-severity SharePoint Server deserialization flaw, to KEV catalog after confirmed active exploitation by threat actors.</description><pubDate>Thu, 02 Jul 2026 07:34:50 GMT</pubDate><category>CVE-2026-45659</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>CVE-2024-38094: 1,300+ SharePoint Servers At Risk of RCE</title><link>https://runtimerebel.com/blog/cve-2024-38094-1300-sharepoint-servers-at-risk-of-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-38094-1300-sharepoint-servers-at-risk-of-rce</guid><description>Over 1,300 Microsoft SharePoint servers remain unpatched against CVE-2024-38094, a critical RCE vulnerability actively exploited by threat actors.</description><pubDate>Wed, 22 Apr 2026 08:43:27 GMT</pubDate><category>CVE-2024-38094</category><category>Microsoft SharePoint</category><category>RCE</category><category>CISA KEV</category><category>Shadowserver</category></item><item><title>CISA KEV Catalog Update: Microsoft Office RCE and SharePoint Exploited</title><link>https://runtimerebel.com/blog/cisa-kev-catalog-update-microsoft-office-rce-and-sharepoint-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-catalog-update-microsoft-office-rce-and-sharepoint-exploited</guid><description>CISA adds CVE-2009-0238 (Microsoft Office RCE) and CVE-2026-32201 (SharePoint Server input validation) to its Known Exploited Vulnerabilities Catalog.</description><pubDate>Tue, 14 Apr 2026 20:27:09 GMT</pubDate><category>CVE-2009-0238</category><category>CVE-2026-32201</category><category>Microsoft Office</category><category>Microsoft SharePoint</category><category>RCE</category><category>CISA KEV</category><category>Vulnerability Management</category></item><item><title>CVE-2026-20963: Microsoft SharePoint Deserialization Exploit — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-20963-microsoft-sharepoint-deserialization-exploit-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20963-microsoft-sharepoint-deserialization-exploit-patch-now</guid><description>CISA adds CVE-2026-20963, a Microsoft SharePoint deserialization vulnerability, to its KEV catalog due to active exploitation.</description><pubDate>Wed, 18 Mar 2026 20:17:46 GMT</pubDate><category>CVE-2026-20963</category><category>Microsoft SharePoint</category><category>Deserialization Vulnerability</category><category>KEV Catalog</category><category>Active Exploitation</category></item></channel></rss>