← The Desk 2026-07-18 The Wire
The Perimeter Site

Your SharePoint Server is a Very Expensive Space Heater

Dana Kessler
2026-07-18
# Your SharePoint Server is a Very Expensive Space Heater The 3am page is the same one we've seen for three years. CISA just updated the KEV. SharePoint RCE. Fortinet FortiSandbox. Both are in the most serious tier of risk we track. If you're on call, you're already caffeinated and wondering why the patch cycle for the collaboration stack is still a manual nightmare. The narrative on the wire this week is that we're witnessing a coordinated "Zero-Day Summer." The consensus is that state-sponsored actors are synchronizing their strikes across edge gear and collaboration servers to cripple critical infrastructure. The evidence cited is the timing. SharePoint and Fortinet hitting the KEV simultaneously, coupled with the American Hospital Association reporting targeted hits on the healthcare sector. It looks like a focused campaign designed to create a systemic failure across the US public sector and health systems. It's a nice story. It's also wrong. Stop looking for a mastermind and look at the numbers. We've seen 242 vulnerability reports this week. North of 87 of those are confirmed as exploited in the wild. This isn't a coordinated campaign. It's a gold rush. When a high-impact RCE like CVE-2026-58644 hits, every script kiddie and ransomware affiliate from here to Novosibirsk is knocking on the same doors. The "coordination" is just the fact that everyone uses the same scanners. The obsession with the "zero-day" label is a distraction. Most of these "sudden" exploitations are just the gap between a vulnerability being used by a few and it being noticed by the masses. The real story isn't the exploit. It's the technical debt. Windows Server 2022 reaches the end of mainstream support in 90 days. Most of the environments getting hit by these SharePoint flaws are running on legacy foundations that should have been decommissioned during the last administration. The strongest objection here is the healthcare targeting. The "coordinated" crowd will argue that the American Hospital Association's warnings prove a strategic intent to target the vulnerable. The answer is simpler. Healthcare is just the easiest target. They have the worst patching cadence and the highest urgency for uptime, which makes them the path of least resistance. Attackers aren't targeting hospitals because of a geopolitical strategy. They're targeting them because the servers are old and the admins are tired. The second-order effect here isn't just downed servers or leaked data. Look at the insurance providers. If the industry accepts the "coordinated state-sponsored campaign" narrative, it gives insurers a convenient exit. Many policies have clauses that void coverage in the event of an "act of war." By rebranding a series of opportunistic attacks as a coordinated campaign, the industry is inadvertently helping insurers avoid paying out millions in ransomware recovery claims. Who benefits if the crowd is wrong? The attackers. While the C-suite is panicking about "nation-state actors" and buying expensive, AI-driven "threat hunting" platforms to find the "invisible" enemy, they're ignoring the basics. They're so focused on the front door that they aren't noticing the local privilege escalation bugs. While you're chasing the SharePoint ghost, someone is using CVE-2026-50454 to move from AppContainer to SYSTEM on your internal workstations. The hype itself is a product. The vendors selling "autonomous patching" and "AI-SOC" tools love the "coordinated campaign" narrative. It creates a sense of urgency that justifies a seven-figure price tag for a tool that mostly just wraps a legacy scanner in a fancy UI. It turns a hygiene problem into a warfare problem. You can't solve warfare with a better patch window, but you can solve it with a "Cognitive Security Suite." We're also seeing the noise floor for data breaches shift. The lawsuit claiming 2.4 billion TikTok users had their data leaked in June is a staggering number. Badoo has 51 million users up for sale. In a vacuum, these are disasters. In reality, they're just updates to a mailing list. The "massive breach" headline is now background radiation. The risk isn't the leak itself; it's the refined phishing campaigns that follow. The Fairlife ransomware attack is the only one that actually matters for the average person because it stopped US milk production. The press is calling it a "sophisticated IT-OT breach." It probably wasn't. It was likely a stolen credential and a flat network. We've seen this movie since 2017. The parallel is perfect, except this time it's milk instead of pipelines. The industry needs to stop treating every KEV update like a declaration of war. It's not a campaign. It's a lack of basic hygiene. If you want to actually secure the environment, stop reading the geopolitical analysis and check your Windows Server versions. If you're still on a version hitting end-of-life in three months, you're not a victim of a coordinated strike. You're just overdue for a migration. Watch the OpenWrt pre-auth remote root exploit. That's where the real dwell time is happening. While the world screams about SharePoint, the attackers are quietly nesting in the edge routers where the logs aren't being sent to the SIEM. That's the move that actually persists. Check the PoC for the AppResolver LPE. It's already on r/netsec. That's the one that lets them stay once they're in.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.