CVE-2023-29357Active Exploitation(microsoft / sharepoint_server)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft sharepoint_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Microsoft SharePoint Server Elevation of Privilege Vulnerability

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-01-31. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-303

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-22); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
sharepoint_server

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-22: 1Mentions · 2026-05-01: 1Mentions · 2026-06-24: 1Mentions · 2026-08-07: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-06-24: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-22: 1Technical Details · 2026-08-07: 104-2205-0106-2408-07
Signal classification3 categories
Active Exploitation
250.0%
General
125.0%
Disclosure
125.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-04-221
General1
2026-05-011
Active Exploitation1
2026-06-241
Active Exploitation1
2026-08-071
Disclosure1
Full discourse4 posts
  • ET Labs@ET_Labs
    Disclosure

    11 new OPEN, 15 new PRO (11 + 4) TA2730, Cisco UCM 15.x Unauth RCE, CVE-2023-29357 (MS Sharepoint Auth Bypass), CVE-2026-45659 (Sharepoint Deserialization RCE), Lumma Stealer, and many more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-08-07-v11252/3413

    Post summary

    The post lists several new CVEs affecting Cisco UCM and Microsoft SharePoint, detailing their basic impact, but provides no PoC, exploit code, evidence of active exploitation, or patch guidance.

    01010275
    5.7K followersView on X
  • ZeroDay Post@ZeroDayPost
    Active Exploitation

    5/ Alert for sysadmins: CISA warns that a critical Microsoft SharePoint vulnerability (CVE-2023-29357) is now being actively exploited by attackers to gain initial access and elevate privileges. Patch now! 🚨

    Post summary

    Microsoft SharePoint CVE-2023-29357 is actively exploited in the wild and users are urged to apply the available patch immediately.

    1001088
    5 followersView on X
  • CyDhaal@CyberDhaal
    Active Exploitation

    2/3 Current attack pattern: • Initial access via unpatched CVEs (including CVE-2023-29357 & CVE-2023-24955) • Custom web shells dropped in sensitive directories (/_layouts/, /_catalogs/, /_vti_bin/) • Privilege escalation using SharePoint service accounts • Lateral movement + ransomware deployment via scheduled tasks or Group Policy • Heavy targeting of healthcare, finance, legal, and government environments Many organizations still run exposed SharePoint 2016/2019/Subscription Edition instances.

    Post summary

    Attackers are exploiting unpatched SharePoint CVEs (CVE-2023-29357 and CVE-2023-24955) by dropping web shells, escalating privileges, and deploying ransomware, with a focus on healthcare, finance, legal, and government sectors.

    1000057
    510 followersView on X
  • Orizon@OrizonCyber
    General

    CVE-2023-29357 lets attackers bypass authentication by manipulating JWT tokens. Microsoft rated it 9.8/10 severity. Public exploits dropped weeks ago, yet here we are with over 1K servers still wide open. Which fortune 500 company will be tomorrow's headline?

    Post summary

    A brief notice highlights CVE-2023-29357 as a high‑severity authentication bypass via JWT manipulation, noting that many servers remain vulnerable but providing no PoC, exploit details, or patch information.

    0000088
    28 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server2019--

Explore more