Discover your interests, together

Real deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Discover your interests, togetherReal deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Two Zero-Day Flaws Under Active Attack: Patch Cisco Firewalls and SharePoint Now

Two Zero-Day Flaws Under Active Attack: Patch Cisco Firewalls and SharePoint Now
Interest|High-Quality Software

Zero-Day Vulnerabilities Are Now Slamming Core Enterprise Systems

A zero-day vulnerability patch is an emergency fix for a previously unknown software flaw that attackers are already exploiting, meaning defenders must prioritize and deploy it immediately to prevent active security threat scenarios where critical systems can be disrupted or taken over before routine update cycles can react. Right now, two such flaws demand attention: a Cisco firewall exploit crashing perimeter defenses, and a SharePoint security flaw enabling silent impersonation inside collaboration platforms. Together they hit both the edge and the core of enterprise infrastructure. This is not a theoretical risk or a compliance checkbox moment; these bugs are being used in the wild, and any delay in patching hands attackers an open door into your environment. If your team treats them as “just another update,” you are gambling with business continuity and data integrity.

Cisco Firewall Zero-Day: Your VPN Gateway Can Be Blinded Instantly

The Cisco firewall exploit tracked as CVE-2026-20349 is a textbook example of why perimeter devices deserve more respect than many patch calendars give them. It abuses an HTTP request processing flaw in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD), letting unauthenticated remote attackers force the firewall into denial-of-service reload loops. In plain terms: any exposed VPN gateway in the affected versions—ASA 9.16 through 9.24 and FTD 7.0 through 10.0 with remote-access SSL VPN enabled—is vulnerable to automated scripts that repeatedly crash and reboot the device, severing connections and causing a continuous blackout. “If the vulnerability is exploited, it results in the firewall abruptly reloading, severing active connections and creating a continuous availability blackout.” There are no workarounds for this issue; patching is the only way to fix it, and postponing that zero-day vulnerability patch is equivalent to accepting that your security operations can be blinded on demand.

Two Zero-Day Flaws Under Active Attack: Patch Cisco Firewalls and SharePoint Now

SharePoint Authentication Bypass: Silent Impersonation Inside Your Collaboration Hub

On the application side, CVE-2026-55040 is a critical SharePoint security flaw that turns your collaboration environment into a playground for impersonation. Microsoft patched it in its July Patch Tuesday, but the story did not end there. After Rapid7 researcher Stephen Fewer released an in-depth technical analysis and proof-of-concept exploit code, threat actors began exploiting the bug against SharePoint honeypots. The vulnerability stems from several issues in the JWT token validation pipeline, allowing a remote unauthenticated attacker to bypass authentication and perform operations as a SharePoint site user or administrator. As Microsoft notes, exploitation can let an attacker disclose files and modify data, even if it does not directly impact availability. Worse, when paired with another flaw, CVE-2026-63520, it “could lead to unauthenticated remote code execution against a vulnerable SharePoint server,” according to NHS England Digital. In other words, this active security threat is a stepping stone to full compromise of one of your most sensitive internal systems.

Immediate Actions: Patch First, Harden SharePoint, Then Rebuild Your Patch Priorities

IT admins should treat both vulnerabilities as top-tier incidents, not background maintenance items. For Cisco ASA and FTD, apply the available zero-day vulnerability patch and any hotfixes immediately; there are no workarounds, so unpatched devices with Remote Access SSL VPN enabled remain exposed. For SharePoint, ensure CVE-2026-55040 is patched across all servers, then harden the deployment following Microsoft’s guidance. CISA advises avoiding direct internet exposure for SharePoint; if exposure is necessary, place it behind a Layer 7 reverse proxy or similar application-layer control that requires authentication and can inspect and filter requests. Administrators are warned to harden SharePoint further, given active exploitation of other vulnerabilities on the platform. The practical takeaway: prioritize these patches over routine updates. With proof-of-concept code public and live exploitation underway, delay is what turns a manageable vulnerability into a full-scale incident.

Conclusion: Stop Treating Edge Devices and Collaboration Platforms as Afterthoughts

These two flaws expose a persistent weakness in enterprise security culture: critical infrastructure patches are too often drowned in routine change queues. A Cisco firewall exploit that can crash your VPN gateway without authentication and has no workaround is not a normal ticket—it is an operational fire. Likewise, a SharePoint security flaw actively targeted after public proof-of-concept release is not a theoretical bug to watch; it is an entry point into your core data and workflows. Defenders have the tools they need: patches exist for both vulnerabilities, and clear hardening guidance is available for SharePoint deployments. What is missing is urgency. Make these fixes the top of your patch list, verify that exposed systems are updated, and revisit your patch strategy to ensure that future active security threats are handled as incidents, not paperwork. Business continuity depends on that shift.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!