• News/
  • https://www.zdnet.com/article/microsoft-fixes-sharepoint-zero-day-exploits-used-in-cyberattacks-and-ransomware-how-to-patch-them/

Microsoft fixes SharePoint zero-day exploits used in cyberattacks and ransomware - how to patch them

ZDNet
·
Lance Whitney
·
Published Jul 24, 2025
·
Updated

Microsoft has patched three critical zero-day SharePoint security flaws that hackers have already exploited to attack more vulnerable organizations. Responding to the exploits, the software giant initially issued fixes just for SharePoint Server Subscription Edition and SharePoint Server 2019, and then eventually rolled out a patch for SharePoint Server 2016 as well. Designated as CVE‑2025‑53771 and CVE‑2025‑53770, the two vulnerabilities apply only to on‑premises versions of SharePoint, so organizations that run cloud‑based SharePoint Online are unaffected. Also: I replaced my Microsoft account password with a passkey - and you should, too Rated as important, CVE‑2025‑53771 is a SharePoint Server spoofing vulnerability, which means attackers can impersonate trusted and legitimate users or resources in a SharePoint environment. Rated as critical, CVE‑2025‑53770 is a SharePoint Server remote code execution vulnerability. With this type of flaw, hackers can run code remotely in a SharePoint environment. "CVE‑2025‑53770 gives a threat actor the ability to remotely execute code, bypassing identity protections (like single sign‑on and multi‑factor authentication), giving access to content on the SharePoint server including configurations and system files, opening up lateral access across the Windows domain," Trey Ford, chief information security officer at crowdsourced cybersecurity provider Bugcrowd, told ZDNET. Together, the two flaws allow cybercriminals to install malicious pr...

Read full article

Affected Software

3 affected components
Microsoft SharePoint Server=Subscription Edition
Microsoft SharePoint Server=2019
Microsoft SharePoint Server=2016
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What security vulnerabilities are addressed in the article?

The article discusses three critical zero-day vulnerabilities in Microsoft SharePoint that have been exploited by hackers.

2

What types of cyber threats are associated with these exploits?

The exploits are linked to cyberattacks and ransomware targeting vulnerable organizations.

3

Which versions of Microsoft SharePoint are affected by these vulnerabilities?

The affected versions include SharePoint Server Subscription Edition, 2019, and 2016.

4

How did Microsoft respond to these security vulnerabilities?

Microsoft released patches to fix the critical zero-day vulnerabilities in SharePoint.

5

What should organizations do to protect themselves from these vulnerabilities?

Organizations should apply the patches provided by Microsoft to mitigate the risks associated with the zero-day exploits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203