- Hackers target on-prem SharePoint servers through a new flaw.
- Microsoft has patched some versions as agencies rush to respond.
A new wave of cyberattacks is hitting SharePoint servers used by government agencies and companies to manage internal documents. Microsoft says hackers are actively exploiting a vulnerability in on-premise versions of its software and has urged users to apply security updates as soon as possible.
The issue affects only on-premise SharePoint systems – those installed and managed directly by the organisation. Microsoft 365’s SharePoint Online, which runs in the cloud, isn’t impacted.
The flaw, tracked as CVE-2025-53770, allows attackers to run code on vulnerable servers from a remote location. That kind of access can lead to serious consequences, including data theft, stolen passwords, or broader system compromise. Microsoft confirmed it has seen real-world attacks using this method and is preparing a full update to fix the issue.
The company has already released a patch for SharePoint Subscription Edition. Fixes for the 2016 and 2019 versions are still in the works. In the meantime, Microsoft is telling users to either enable malware protection or, if that’s not possible, disconnect affected servers from the internet until updates are available.
Australia’s cyber agency, the ACSC, echoed that warning and advised system administrators to keep a close watch on Microsoft’s official advisories for updates and fixes.
The FBI said on Sunday it is aware of the attacks and is working with federal agencies and private companies, but it hasn’t released further details.
According to The Washington Post, which broke the story, unknown attackers have used the flaw to breach government and business systems both in the US and abroad. The attacks are being described as a “zero-day” exploit – an attack that takes advantage of a software flaw before the developer knows about it or can issue a fix. Experts told the paper that tens of thousands of servers could be at risk.
What makes this attack especially concerning is the kind of access attackers are gaining. Netherlands-based security firm Eye Security said hackers aren’t just getting into servers – they’re stealing cryptographic keys that may let them return even after patches are applied. In some cases, they may be able to move laterally through networks and reach other connected systems.
One researcher, who spoke anonymously due to an ongoing federal investigation, warned that patching now won’t help anyone who was already compromised in recent days. “So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” they said.
More than 50 breaches have already been reported by researchers tracking the issue. Victims include at least two US federal agencies, an energy company in a large US state, and several government offices in Europe. One private research team also found attackers targeting servers in China and a state legislature in the eastern United States.
One state official said the attackers had taken control of a public-facing SharePoint site meant to help residents understand how their local government works. “We will need to make these documents available again in a different repository,” the official said. It’s still unclear whether the original files were deleted or just made inaccessible.
Most intrusions to date appear to focus on stealing information and keys rather than deleting data. But reports of possible “wiper” activity – where data is permanently destroyed – have other states on alert.
The attacks come just weeks after Microsoft patched a previous SharePoint flaw. According to the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), the attackers spotted a similar weakness and exploited it. CISA said it was alerted by a cybersecurity firm last Friday and immediately contacted Microsoft.
This isn’t the first time Microsoft’s response to security issues has come under fire. The company has faced criticism for releasing narrow fixes that don’t always cover related risks. It’s also had to deal with major breaches over the past two years, including incidents where hackers accessed internal Microsoft systems and email accounts belonging to US government officials.
In its latest alert, Microsoft also pointed to another vulnerability that could allow spoofing – where attackers impersonate a trusted user or system to gain access. While that issue is separate, it highlights the broader concerns about how attackers are working to blend in with normal network traffic.
Microsoft said it’s continuing to work on fixes and will share more details as they become available. For now, system admins are being told to patch what they can, stay alert for signs of compromise, and disconnect vulnerable servers if there’s no other option.
Author
View all postsAs a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.