Microsoft 365 just nu

Nyheter, sårbarheter och attacker

Det som hänt kring Microsoft 365, hämtat från Microsoft och CISA. Inga tolkningar, inga rykten: varje rad länkar till originalkällan. Uppdateras varje timme.

Sårbarheter i Microsoft-produkter som bevisligen utnyttjas i attacker just nu, plus Microsofts egna rapporter om pågående kampanjer. Det här är listan att agera på först.

  1. Microsoft Security Blog
    Unmasking EvilTokens: Getting to the root of device code phishing
    Adversary-in-the-middle (AiTM)Phishing
  2. Microsoft Security Blog
    Detect and disrupt AI-themed attacks with Microsoft Defender
    Adversary-in-the-middle (AiTM)Credential theft
  3. Microsoft Security Blog
    Threat matrix: Mapping threats across cloud web applications
  4. Microsoft Security Blog
    Passkey-themed social engineering leads to identity and cloud compromise
    Social engineering
  5. CISA, aktivt utnyttjad
    CVE-2026-81963: Microsoft Windows Link Following Vulnerability

    Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

    Windows
  6. CISA, aktivt utnyttjad
    CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability

    Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

    Windows
  7. Microsoft Security Blog
    ASCII smuggling crosses over from AI prompt injection to phishing evasion
    PhishingSocial engineering
  8. Microsoft Security Blog
    Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
  9. CISA, aktivt utnyttjad
    CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability

    Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

    SQL Server
  10. CISA, aktivt utnyttjad
    CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

    Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

    Internet Key Exchange (IKE) Service Extensions
  11. CISA, aktivt utnyttjad
    CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability

    Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

    SharePoint
  12. CISA, aktivt utnyttjad
    CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

    Windows Ancillary Function Driver for WinSock
  13. CISA, aktivt utnyttjad
    CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

    SharePoint
  14. CISA, aktivt utnyttjad
    CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

    SharePoint
  15. CISA, aktivt utnyttjad
    CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

    Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally

    Active Directory Federation Services
  16. CISA, aktivt utnyttjad
    CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

    Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

    SharePoint Server
  17. CISA, aktivt utnyttjad
    CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

    Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

    SharePoint ServerAnvänds i utpressningsattacker
  18. CISA, aktivt utnyttjad
    CVE-2008-4250: Microsoft Windows Buffer Overflow Vulnerability

    Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that trigg

    Windows
  19. CISA, aktivt utnyttjad
    CVE-2009-1537: Microsoft DirectX NULL Byte Overwrite Vulnerability

    Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitr

    DirectX
  20. CISA, aktivt utnyttjad
    CVE-2010-0249: Microsoft Internet Explorer Use-After-Free Vulnerability

    Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted ob

    Internet Explorer
  21. CISA, aktivt utnyttjad
    CVE-2010-0806: Microsoft Internet Explorer Use-After-Free Vulnerability

    Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer

    Internet Explorer
  22. CISA, aktivt utnyttjad
    CVE-2026-41091: Microsoft Defender Link Following Vulnerability

    Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

    Defender
  23. CISA, aktivt utnyttjad
    CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability

    Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

    Defender
  24. CISA, aktivt utnyttjad
    CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting Vulnerability

    Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary

    Microsoft
  25. CISA, aktivt utnyttjad
    CVE-2026-32202: Microsoft Windows Protection Mechanism Failure Vulnerability

    Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

    Windows
  26. CISA, aktivt utnyttjad
    CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability

    Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

    DefenderAnvänds i utpressningsattacker
  27. CISA, aktivt utnyttjad
    CVE-2009-0238: Microsoft Office Remote Code Execution

    Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafte

    Office
  28. CISA, aktivt utnyttjad
    CVE-2026-32201: Microsoft SharePoint Server Improper Input Validation Vulnerability

    Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.

    SharePoint Server
  29. CISA, aktivt utnyttjad
    CVE-2012-1854: Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

    Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.

    Visual Basic for Applications (VBA)
  30. CISA, aktivt utnyttjad
    CVE-2025-60710: Microsoft Windows Link Following Vulnerability

    Microsoft Windows contains a link following vulnerability that allows for privilege escalation

    WindowsAnvänds i utpressningsattacker
  31. CISA, aktivt utnyttjad
    CVE-2023-21529: Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

    Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

    Exchange ServerAnvänds i utpressningsattacker
  32. CISA, aktivt utnyttjad
    CVE-2023-36424: Microsoft Windows Out-of-Bounds Read Vulnerability

    Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

    Windows
  33. CISA, aktivt utnyttjad
    CVE-2026-20963: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

    SharePoint
  34. CISA, aktivt utnyttjad
    CVE-2008-0015: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

    Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. Wh

    Windows
  35. CISA, aktivt utnyttjad
    CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability

    Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the t

    Configuration Manager
  36. CISA, aktivt utnyttjad
    CVE-2026-21513: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

    Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

    Windows
  37. CISA, aktivt utnyttjad
    CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability

    Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.

    Windows
  38. CISA, aktivt utnyttjad
    CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability

    Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

    Windows
  39. CISA, aktivt utnyttjad
    CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability

    Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.

    Windows
  40. CISA, aktivt utnyttjad
    CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability

    Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.

    Windows

Källor: Microsoft 365 Roadmap, Microsoft Security Response Center, CISA Known Exploited Vulnerabilities och Microsoft Security Blog. Rubrikerna är på engelska eftersom källorna är det. Senast hämtat 23 sep. 2026.

← Tillbaka till KOLLEN