The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are actively exploiting three vulnerabilities in Internet-exposed on-premises SharePoint Server instances. Organizations running affected versions must patch immediately.
CISA issued an urgent advisory Tuesday detailing three SharePoint Server vulnerabilities currently being weaponized in the wild. The flaws affect on-premises installations exposed to the internet, putting organizations at immediate risk of compromise.
The vulnerabilities allow attackers to gain unauthorized access to SharePoint servers and potentially execute malicious code. CISA did not disclose specific vulnerability details to prevent wider exploitation, but emphasized the critical nature of the threats.
Affected administrators should prioritize patching over other non-critical updates. Microsoft has released security patches addressing these flaws, and CISA recommends applying them without delay.
SharePoint Server remains a common target for attackers due to its widespread deployment in enterprise environments and the sensitive data it often contains. Organizations that fail to patch face heightened risk of data theft, ransomware deployment, and lateral movement within their networks.
CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling that federal agencies and critical infrastructure operators must patch within specific timeframes under binding operational directives.
Administrators should verify their SharePoint deployment status, identify exposed instances, and apply available security updates immediately. Organizations unable to patch quickly should consider taking affected systems offline or restricting network access until updates are deployed.
The alert underscores the ongoing threat landscape for enterprise collaboration platforms. Security researchers continue discovering new ways to exploit outdated software, making timely patching essential for network defense.
Illinois county prosecutors secretly provided personal information about criminal defendants to federal immigration agents without warrants, public disclosure, or legislative approval.
Law enforcement from 22 countries arrested 58 individuals and identified 263 suspects in a coordinated crackdown on cybercrime networks run by African crime groups.
The Los Angeles County Museum of Art disclosed a data breach from last year that compromised customer and employee information, including social security numbers and medical records.
A phishing-as-a-service platform called AnonyMousKIT uses voice AI agents to extract passcodes from stolen Apple devices and bypass Activation Lock security features.