Cyber Security News

CISA Warns Active Exploitation of Microsoft SharePoint Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities Catalog following evidence of its active exploitation.

CVE-2024-38094 vulnerability affects Microsoft SharePoint and is categorized as a deserialization vulnerability.

Malicious cyber actors often target this type of security flaw because it can allow unauthorized remote code execution.

The vulnerability was initially disclosed on July 9, 2024, and has been assigned a maximum severity rating of “Important” by Microsoft, with a CVSS score of 7.2.

National Cybersecurity Awareness Month Cyber Challenges – Test your Skills Now

The weakness stems from the deserialization of untrusted data, classified under CWE-502.

Attackers can exploit such vulnerabilities to execute arbitrary code on affected systems, posing significant risks to organizations that rely on SharePoint for collaboration and data management.

CISA’s inclusion of this vulnerability in its catalog underscores its potential threat to the federal enterprise.

Under Binding Operational Directive (BOD) 22-01, federal agencies must address these known vulnerabilities by specified deadlines to safeguard their networks against active threats.

The directive emphasizes the importance of timely remediation as part of comprehensive vulnerability management practices. 

While BOD 22-01 targets explicitly Federal Civilian Executive Branch (FCEB) agencies, CISA strongly advises all organizations to prioritize the remediation of cataloged vulnerabilities.

This proactive approach is crucial for reducing cyberattack exposure and protecting sensitive information.

CISA’s ongoing efforts to update the Known Exploited Vulnerabilities Catalog reflect its commitment to enhancing national cybersecurity resilience.

Organizations are encouraged to stay informed about emerging threats and implement robust security measures to mitigate risks associated with exploited vulnerabilities. 

By addressing vulnerabilities like CVE-2024-38094 promptly, organizations can better defend against potential attacks and ensure the integrity and security of their digital assets.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Watch Here

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

3 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

8 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

13 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

19 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

30 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago