Microsoft Warns SharePoint Zero-Day Attacks Persist After 2 Patch Failures
Updated
Updated · The Register · Jul 26
Microsoft Warns SharePoint Zero-Day Attacks Persist After 2 Patch Failures
3 articles · Updated · The Register · Jul 26
Summary
Two failed fixes have left Microsoft’s on-premises SharePoint under active zero-day attack, with attackers exploiting vulnerabilities despite the company’s patches.
On-prem SharePoint—not Microsoft 365—is the affected target, making self-hosted enterprise deployments the immediate risk area for compromise.
The failed remediation means organizations that already applied Microsoft’s updates may still be exposed, raising pressure for new guidance or replacement patches.
The incident adds to a broader run of high-impact enterprise software flaws, where incomplete fixes can turn patching itself into a false sense of security.