Updated
Updated · The Register · Jul 26
Microsoft Warns SharePoint Zero-Day Attacks Persist After 2 Patch Failures
Updated
Updated · The Register · Jul 26

Microsoft Warns SharePoint Zero-Day Attacks Persist After 2 Patch Failures

3 articles · Updated · The Register · Jul 26

Summary

  • Two failed fixes have left Microsoft’s on-premises SharePoint under active zero-day attack, with attackers exploiting vulnerabilities despite the company’s patches.
  • On-prem SharePoint—not Microsoft 365—is the affected target, making self-hosted enterprise deployments the immediate risk area for compromise.
  • The failed remediation means organizations that already applied Microsoft’s updates may still be exposed, raising pressure for new guidance or replacement patches.
  • The incident adds to a broader run of high-impact enterprise software flaws, where incomplete fixes can turn patching itself into a false sense of security.

Insights

Microsoft’s SharePoint patches failed twice—how can admins tell if patching fixed the flaw or only left a hidden backdoor behind?
Why are on-premises SharePoint servers becoming ideal entry points for attackers, and what connected systems are most at risk next?
If CISA says exposed SharePoint may already be compromised, when should organizations patch, isolate, or shut systems down completely?