SharePoint exploit chain creates unauthenticated remote code execution risk

Website copy

Two vulnerabilities affecting on-premises Microsoft SharePoint Server can form a SharePoint exploit chain capable of unauthenticated remote code execution. Exploitation attempts targeting CVE-2026-55040 were observed shortly after public proof-of-concept code was released.The chain combines an authentication bypass with a remote code execution flaw, removing the need for legitimate credentials and placing internet-facing SharePoint deployments at heightened risk. Organisations should prioritise remediation of both flaws and monitor for anomalous authentication, unusual privileged-user behaviour and signs of server compromise.Find out more about Orpheus cyber threat intelligence.What happenedAn Iran-linked cyberattack reportedly took an unnamed small UK energy generator offline for four days in July. The government confirmed that an incident affected a small generator but said the wider energy system was never at risk.Why it mattersThe shutdown shows that a cyberattack against one small generator can cause sustained operational disruption without affecting the wider grid. If the Iran link is confirmed, it may indicate a willingness to disrupt individual UK energy assets or test access ahead of future activity. The lack of technical evidence and confirmed attribution limits confidence in assessing the likelihood of similar incidents.Also in this week’s summaryShinyHunters’ vishing operation against ReliaQuest employees, data theft affecting Italian schools, critical PaperCut and cPanel vulnerabilities, and flaws affecting NVIDIA NemoClaw and Gitea.

Download the full Weekly Intelligence Summary

Weekly Intelligence Summary: Iran linked cyberattack uk energy generator
Scroll to Top

Become a Partner

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Please complete the form below and we’ll be in touch shortly.