The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are actively exploiting three vulnerabilities in Internet-exposed on-premises SharePoint Server instances. Organizations running affected versions must patch immediately.
CISA issued an urgent advisory Tuesday detailing three SharePoint Server vulnerabilities currently being weaponized in the wild. The flaws affect on-premises installations exposed to the internet, putting organizations at immediate risk of compromise.
The vulnerabilities allow attackers to gain unauthorized access to SharePoint servers and potentially execute malicious code. CISA did not disclose specific vulnerability details to prevent wider exploitation, but emphasized the critical nature of the threats.
Affected administrators should prioritize patching over other non-critical updates. Microsoft has released security patches addressing these flaws, and CISA recommends applying them without delay.
SharePoint Server remains a common target for attackers due to its widespread deployment in enterprise environments and the sensitive data it often contains. Organizations that fail to patch face heightened risk of data theft, ransomware deployment, and lateral movement within their networks.
CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling that federal agencies and critical infrastructure operators must patch within specific timeframes under binding operational directives.
Administrators should verify their SharePoint deployment status, identify exposed instances, and apply available security updates immediately. Organizations unable to patch quickly should consider taking affected systems offline or restricting network access until updates are deployed.
The alert underscores the ongoing threat landscape for enterprise collaboration platforms. Security researchers continue discovering new ways to exploit outdated software, making timely patching essential for network defense.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.
The Bureau of Alcohol, Tobacco, Firearms and Explosives has notified Congress of a major cybersecurity incident after a ransomware gang claimed responsibility for breaching the agency's systems.
Google is rolling out Encrypted Client Hello (ECH) support in Android 17 to prevent network monitoring of user browsing activity. The privacy feature strengthens connection security across cellular and home networks.
A new survey shows more Americans oppose police use of license plate readers than support them. The finding reflects growing concerns about surveillance overreach.