Blog / tag

A critical deserialization flaw in Microsoft SharePoint (CVSS 9.8) is being actively exploited in the wild, and its patch quietly shipped in June before public disclosure on July 14. Organizations that skipped a monthly update may already be compromised.

CISA added CVE-2008-0015 to its Known Exploited Vulnerabilities catalog on February 17, 2026, confirming active exploitation of a critical stack-based buffer overflow in Microsoft's Video ActiveX control that allows complete system takeover via a malicious webpage.

Microsoft patched CVE-2026-20805, a Desktop Window Manager information disclosure flaw actively exploited to defeat memory protections. CISA added it to the KEV catalog, requiring federal agencies to patch by February 3, 2026.