Microsoft has confirmed that vulnerabilities in its on-premises SharePoint Server installations, a network spoofing vulnerability (CVE-202549706), and a remote code execution vulnerability (CVE-2025-49704) are being actively exploited despite releasing an emergency patch on July 20, 2025. The vulnerabilities allow threat actors to “execute code remotely, bypass identity protections such as multi-factor authentication and access system
Microsoft Outlook
U.S. Cyber Command Issues Warning About Microsoft Outlook Vulnerability
By Linn Foster Freedman on
Posted in Cybersecurity
Hackers are targeting U.S. government networks, according to U.S. Cyber Command, which says there is a vulnerability of CVE-2017-1174, which is a two year old flaw in Microsoft Outlook that is being used by attackers to install remote access Trojans and other malware.
U.S. Cyber Command recommends that the vulnerability be patched to prevent exploitation.…