Microsoft is aware of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities CVE-2025-53771 that could allow a cyber attacker to trick SharePoint into giving access to files. The vulnerabilities have been partially addressed by the July Security Update. Customers are required to install the security updates immediately followed by the additional security measures described in this article.
Note: These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted.
Mitigation
Microsoft has released security updates that protect customers using SharePoint Servers. Customers are required to apply these updates immediately to ensure they’re protected.
Product | KB Article |
Microsoft Sharepoint Subscription Edition | KB5002768 |
Microsoft Sharepoint Server 2019 | KB5002754 |
Microsoft Sharepoint Enterprise Server 2016 | KB5002744 |
To mitigate potential attacks customers should:
Conclusion
Helient strongly recommends customers be aware of the active exploits happening in On-Premise SharePoint Servers and take necessary actions to apply the zero-day security updates asap. If you would like more information or assistance, please contact our industry-leading experts at service@helient.com.