I don't know how this didn't go out yesterday, but I tried posting this earlier.
This is a now patchable issue with SharePoint. It is very trivial to exploit once you understand how to cobble together the pieces. It's actively being exploited. Patches came out today. Check to see if you have been popped....
I am speaking at the South Florida ISSA Meeting Tonight. It's in the same venue as the HackMiami conference. If you are in the area and want to hang out, here are the details:
https://www.meetup.com/south-florida-issa-chapter/events/307512862
If you see the following header in your weblogs and your running next.js ... well...
x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware
#CVE-2025-29927