Website copy
Two vulnerabilities affecting on-premises Microsoft SharePoint Server can form a SharePoint exploit chain capable of unauthenticated remote code execution. Exploitation attempts targeting CVE-2026-55040 were observed shortly after public proof-of-concept code was released.
The chain combines an authentication bypass with a remote code execution flaw, removing the need for legitimate credentials and placing internet-facing SharePoint deployments at heightened risk. Organisations should prioritise remediation of both flaws and monitor for anomalous authentication, unusual privileged-user behaviour and signs of server compromise.
Find out more about Orpheus cyber threat intelligence.
What happened
An Iran-linked cyberattack reportedly took an unnamed small UK energy generator offline for four days in July. The government confirmed that an incident affected a small generator but said the wider energy system was never at risk.
Why it matters
The shutdown shows that a cyberattack against one small generator can cause sustained operational disruption without affecting the wider grid. If the Iran link is confirmed, it may indicate a willingness to disrupt individual UK energy assets or test access ahead of future activity. The lack of technical evidence and confirmed attribution limits confidence in assessing the likelihood of similar incidents.
Also in this week’s summary
ShinyHunters’ vishing operation against ReliaQuest employees, data theft affecting Italian schools, critical PaperCut and cPanel vulnerabilities, and flaws affecting NVIDIA NemoClaw and Gitea.