Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

SharePoint RCE is being exploited now. Are your controls ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Microsoft SharePoint Server unauthenticated RCE is already being exploited in the wild, while CISA KEV listings also highlight active risk across Exchange, ColdFusion, UniFi, WordPress, and other exposed systems, according to Senserva. The pattern is clear: exploitation evidence, not severity alone, should drive patch order and hunting.

NHIMG editorial — based on content published by Senserva: SharePoint Server unauthenticated RCE is being exploited now

By the numbers:

Questions worth separating out

Q: What breaks when a public application server is hit by unauthenticated RCE?

A: The server stops being just an application tier and becomes a potential access bridge.

Q: Why do KEV-listed vulnerabilities deserve faster action than high-CVSS bugs?

A: KEV-listed flaws already have evidence of exploitation, which means attackers are actively prioritising them.

Q: How do security teams know if an exploited server has become a persistence risk?

A: Look for web shells, unusual child processes, new scheduled tasks, abnormal outbound connections, and unexpected file changes on the application host.

Practitioner guidance

  • Patch KEV-listed server flaws first Reorder remediation so publicly exploited SharePoint, Exchange, ColdFusion, UniFi, and similar internet-facing flaws are patched before lower-risk backlog items.
  • Hunt for web shells after remediation Inspect patched SharePoint and other exposed application servers for web shells, unusual script files, and suspicious child processes.
  • Review secrets on compromised or exposed hosts Check whether the affected server could access service account credentials, API keys, certificates, or delegated tokens.

What's in the full article

Senserva's full article covers the operational detail this post intentionally leaves for the source:

  • The full KEV and EPSS-ranked patch list for Microsoft and non-Microsoft products in this cycle.
  • The specific CISA, Rapid7, SecurityWeek, and vendor references behind each exploited CVE.
  • The Microsoft Patch Tracker workflow used to rank open vulnerabilities by KEV and ransomware linkage.
  • The non-Microsoft exploited-CVE tracker that follows new KEV additions daily.

👉 Read Senserva's live exploitation roundup for SharePoint, Exchange, and other KEV-listed flaws →

SharePoint RCE is being exploited now. Are your controls ready?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Exploitation evidence, not severity, is now the primary patching governor. CVSS tells teams how bad a flaw could be, but KEV status and live exploitation tell them where attackers are already spending effort. That changes remediation from a calendar exercise into an exposure-response exercise. Organisations that still patch by score rather than by evidence leave their most reachable systems open during the window that matters most.

A few things that frame the scale:

  • When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases, according to LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
  • Another NHIMG finding shows that the average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities.

A question worth separating out:

Q: Who is accountable when exposed credentials are used in an attack?

A: Accountability usually sits across IAM, security operations, application owners, and platform teams because the failure is rarely isolated. If the credential was created, stored, or shared outside policy, ownership needs to be explicit before the incident happens. Post-incident, the key question is which control failed to revoke access before misuse became possible.

👉 Read our full editorial: Sharepoint rce and active exploitation are driving urgent patching



   
ReplyQuote
Share: