Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Microsoft_SharePoint

Microsoft_SharePoint Vendor Cyber Rating & Cyber Score

hub.am

SharePoint is capable of improving organizational effectiveness with comprehensive content management, accelerated shared business processes, and information-sharing for better business insight.


Microsoft_SharePoint A.I CyberSecurity Scoring

Microsoft_SharePoint
Company Information
Website:http://hub.am/1gyqTRp
Employees number:None
Number of followers:0
NAICS:5112
Industry Type:Software Development
Homepage:hub.am
Microsoft_SharePoint Risk Score (AI oriented)
Between 650 and 699
logo
Microsoft_SharePointSoftware Development
Updated:
13/08/2026
666/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Microsoft_SharePoint Global Score (TPRM)
xxxx
logo
Microsoft_SharePointSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Microsoft_SharePoint
Microsoft_SharePointWeak
Current Score
666B (WEAK)
01000
12 incidents
-14 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
668Before Incident
AUGUST 2026
666Before Incident
JULY 2026
734Before Incident
Breach
28 Jul 2026Microsoft_SharePoint
Swiss Federal Office for Information Technology and Telecommunication: Swiss Government SharePoint Breach Compromised 200 Accounts

Swiss Federal SharePoint Breach Exposes 200 Accounts in Credential Theft Incident

665After Incident
MEDIUM-69
SWI1786128838
Swiss Federal SharePoint Breach Exposes 200 Accounts in Credential Theft Incident Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) revealed a network intrusion targeting its federal SharePoint platform, resulting in the compromise of approximately 200 user accounts. Unusual activity was detected on July 28, with security specialists confirming the credential theft by July 31. No ransomware group has claimed responsibility, and BIT has not disclosed the specific vulnerability exploited. Investigators suspect the attack leveraged one of two SharePoint flaws patched in Microsoft’s July 2026 Patch Tuesday updates: CVE-2026-56164, a privilege escalation vulnerability actively exploited in the wild, or CVE-2026-50522, a critical remote code execution flaw that could allow attackers to steal SharePoint machine keys and maintain persistence. BIT has not confirmed which flaw was used, but the latter’s ability to enable long-term access raises concerns. While the breach exposed login credentials, BIT stated that the affected SharePoint platform does not store confidential or highly sensitive personal data, and no evidence suggests data exfiltration beyond the stolen credentials. The incident’s impact is thus limited to credential compromise rather than broader data theft. BIT responded swiftly to contain the breach, blocking external internet access to the SharePoint servers, applying patches, resetting affected account passwords, and reinstalling compromised servers. Federal employees have temporarily shifted to alternative file-sharing methods while remediation continues. The investigation involves collaboration with the Swiss Federal Office for Cyber Security and Microsoft. The breach underscores the high-value nature of government collaboration platforms, which often integrate with federal identity systems and shared documents. Even when data theft is not confirmed, credential compromise can pose political and supply-chain risks. The incident also highlights the urgency of applying critical patches attackers exploited flaws addressed in routine updates, demonstrating that delayed deployment can leave systems vulnerable. For other SharePoint deployments, the Swiss case serves as a cautionary example: rapid detection and containment limited the breach’s scope, preventing a potential full-tenant takeover. The ability to steal machine keys linked to CVE-2026-50522 could have allowed attackers to maintain persistent access, reinforcing the need for heightened monitoring of administrative accounts and key-management systems. The incident also reveals broader challenges in public-sector cybersecurity, including reliance on a single commercial platform and difficulties in detecting subtle credential abuse within large-scale collaboration environments. Other national administrations running SharePoint are now advised to verify the July 2026 patches, audit machine key storage, and ensure elevated accounts receive the same scrutiny as standard users.
INCIDENT DETAILS -
TYPE
Credential Theft
IMPACT
Data Compromised: Login credentials of ~200 accountsSystems Affected: Federal SharePoint platformOperational Impact: Temporary shift to alternative file-sharing methods
DATA BREACH
Type Of Data Compromised: Login credentialsNumber Of Records Exposed: 200Sensitivity Of Data: Low (no confidential or highly sensitive personal data)
Vulnerability
28 Jul 2026Microsoft_SharePoint
Microsoft and Federal Office for Information Technology and Telecommunication: Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts

Swiss Federal SharePoint Servers Hit by Cyberattack, Credentials Compromised

665After Incident
LOW-69
FEDMIC1786112922
Swiss Federal SharePoint Servers Hit by Cyberattack, Credentials Compromised Swiss authorities confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and Telecommunication (BIT), resulting in the compromise of approximately 200 user and technical accounts. The incident was detected on July 28 after security teams observed unusual activity in the agency’s SharePoint environment. Investigators suspect the breach exploited recently disclosed Microsoft SharePoint vulnerabilities, which were patched in mid-July. While BIT had begun applying security updates, threat actors may have struck before defenses were fully deployed. The attackers’ identity, origin, and motives remain unknown. On July 31, forensic analysis revealed that login credentials including both standard user accounts and system-level technical accounts had been accessed. BIT responded by resetting all affected passwords. Authorities stated there is no evidence of data exfiltration, and the compromised SharePoint environment does not store highly sensitive government or personal information. As a precaution, BIT has blocked external internet access to the affected servers and is reinstalling the systems. Internal document access remains available, with alternative methods in place for external collaboration. The agency is working with the Federal Office for Cyber Security (BACS) and Microsoft to assess the full scope of the intrusion. The incident underscores the risks of internet-facing collaboration platforms like SharePoint, which are frequent targets due to their role in document storage and internal workflows. BIT reported the breach to BACS and the State Secretariat for Security Policy (SEPOS) in compliance with Switzerland’s Information Security Act and shared technical indicators to help other organizations detect similar threats. The investigation remains ongoing.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Data Compromised: Approximately 200 user and technical accounts compromisedSystems Affected: SharePoint serversOperational Impact: External internet access blocked to affected servers; alternative methods for external collaboration implemented
DATA BREACH
Type Of Data Compromised: User and technical account credentialsNumber Of Records Exposed: 200Sensitivity Of Data: Not highly sensitive (does not store highly sensitive government or personal information)Data Exfiltration: No evidence of data exfiltration
JULY 2026
739Before Incident
Vulnerability
16 Jul 2026Microsoft_SharePoint
Microsoft: CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks

Critical Microsoft SharePoint Vulnerability Under Active Exploitation (CVE-2026-58644)

734After Incident
CRITICAL-5
MIC1784283944
Critical Microsoft SharePoint Vulnerability Under Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-58644, a critical Microsoft SharePoint vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog after confirming real-world attacks. The flaw, classified under CWE-502 (unsafe deserialization), allows unauthenticated remote code execution (RCE) when an attacker sends maliciously crafted serialized data to a vulnerable SharePoint server. Exploitation of this vulnerability could enable threat actors to deploy web shells, move laterally within networks, or launch further attacks, posing severe risks to enterprise and government environments where SharePoint is widely used for document management and collaboration. While no specific ransomware campaigns have been linked to this flaw, deserialization vulnerabilities are a favored attack vector for both ransomware groups and advanced persistent threats (APTs) due to their reliability and high impact. CISA added CVE-2026-58644 to the KEV catalog on July 16, 2026, mandating federal agencies to remediate the issue under Binding Operational Directive (BOD) 26-04. Organizations must assess whether their SharePoint instances are internet-facing and apply Microsoft’s patches or mitigations within CISA’s specified timeframe. If immediate fixes are not feasible, CISA recommends disabling the vulnerable service until protections are in place. To detect potential compromises, security teams are advised to review logs, monitor for unusual SharePoint activity, and investigate indicators such as unexpected processes or unauthorized file uploads. Additional defensive measures include restricting external access to SharePoint servers, enabling endpoint detection and response (EDR) tools, and conducting threat hunting. Given SharePoint’s prevalence in enterprise and government networks, the active exploitation of CVE-2026-58644 underscores the urgency of patching, continuous monitoring, and adherence to CISA’s directives to mitigate risks.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
RansomwareAdvanced Persistent Threats (APTs)
IMPACT
Systems Affected: Microsoft SharePoint serversOperational Impact: Potential lateral movement, unauthorized access, and further attacks
JULY 2026
743Before Incident
Vulnerability
14 Jul 2026Microsoft_SharePoint
Microsoft: CISA Warns of Microsoft SharePoint Server Vulnerability Actively Exploited in Attacks

Critical Microsoft SharePoint Vulnerability Under Active Exploitation (CVE-2026-56164)

739After Incident
CRITICAL-4
MIC1784118231
Critical Microsoft SharePoint Vulnerability Under Active Exploitation The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-56164, a severe vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog after confirming real-world exploitation. The flaw, classified as a missing-authentication vulnerability (CWE-306), allows unauthenticated attackers to remotely escalate privileges on on-premises SharePoint deployments. Exploitation of this vulnerability grants attackers elevated access, enabling them to compromise sensitive documents, modify content, create unauthorized accounts, or move laterally within connected systems. While CISA has not linked the flaw to ransomware campaigns, internet-facing SharePoint servers often containing business-critical data and integrations remain prime targets. CISA added the vulnerability to its KEV catalog on July 14, 2026, with a remediation deadline of July 17, 2026, requiring federal agencies to patch or mitigate the issue within three days. Organizations are urged to prioritize externally accessible SharePoint instances, apply Microsoft’s security updates, and follow Binding Operational Directive (BOD) 26-04 for risk-based patching. If patches are unavailable, CISA recommends discontinuing use of affected products or implementing compensating controls, such as restricting public access, enforcing network segmentation, and isolating compromised systems. Security teams should conduct threat hunting and forensic analysis, monitoring for unusual authentication activity, unauthorized privilege changes, web shells, and abnormal document access. Given the potential for privilege escalation and broader network compromise, defenders are advised to assume that a breached SharePoint server could provide attackers with access to additional enterprise resources.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Sensitive documents, business-critical dataSystems Affected: Microsoft SharePoint Server (on-premises deployments)Operational Impact: Unauthorized account creation, content modification, lateral movement
DATA BREACH
Type Of Data Compromised: Sensitive documents, business-critical dataSensitivity Of Data: High
JULY 2026
748Before Incident
Vulnerability
13 Jul 2026Microsoft_SharePoint
Microsoft: Hackers Actively Exploiting Microsoft SharePoint Vulnerability Following PoC Release

Critical Microsoft SharePoint Authentication Bypass Exploited in the Wild

738After Incident
CRITICAL-10
MIC1786623910
Critical Microsoft SharePoint Authentication Bypass Exploited in the Wild Within Hours of Disclosure Threat actors have rapidly weaponized a newly disclosed critical vulnerability in Microsoft SharePoint, launching attacks against internet-facing servers mere hours after security firm Rapid7 published a technical breakdown and proof-of-concept (PoC) exploit. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), allows unauthenticated attackers to forge authentication tokens and impersonate any SharePoint user including administrators without requiring passwords or session cookies. Rapid7 researcher Stephen Fewer detailed the exploit in a write-up, revealing that the vulnerability stems from four weaknesses in SharePoint’s JWT (JSON Web Token) validation pipeline. Attackers can craft a token with an "alg: none" header, bypass signature checks by leveraging SharePoint’s exposed security token service certificate, and submit a placeholder signature to trick the system into accepting the forged token. The PoC further automates the process by querying domain controllers to identify and impersonate site administrators. Microsoft patched CVE-2026-55040 in its July 2026 Patch Tuesday update, describing it as a weak authentication issue enabling impersonation. Successful exploitation could allow attackers to disclose files and modify data, though system availability remains unaffected. The flaw impacts on-premises deployments including SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 while SharePoint Online remains unaffected. Despite the patch’s availability, researchers warn that thousands of unpatched, internet-exposed SharePoint servers remain vulnerable. The threat is compounded by the flaw’s potential chaining with CVE-2026-63520, a separate remote code execution vulnerability disclosed in Microsoft’s August 2026 Patch Tuesday, which could escalate attacks from impersonation to full system compromise. Threat intelligence firm Defused confirmed active exploitation, noting that attackers were repurposing Rapid7’s PoC against exposed systems. Organizations are advised to apply the July and August 2026 security updates, restrict internet access to SharePoint servers, and monitor authentication logs for anomalous token activity.
INCIDENT DETAILS -
TYPE
Authentication Bypass
IMPACT
Data Compromised: Files disclosed and modifiedSystems Affected: Microsoft SharePoint Server (on-premises deployments)Operational Impact: Unauthenticated impersonation of users, including administrators
DATA BREACH
Type Of Data Compromised: Files and data
JULY 2026
757Before Incident
Vulnerability
01 Jul 2026Microsoft_SharePoint
Microsoft: Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

Critical SharePoint Server Flaw Enables Unauthenticated Remote Code Execution

747After Incident
CRITICAL-10
MIC1786515825
Critical SharePoint Server Flaw Enables Unauthenticated Remote Code Execution Security researchers at Rapid7 Labs have disclosed a severe vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, which allows attackers to execute malicious code remotely without authentication. The flaw, part of a two-part exploit chain alongside CVE-2026-55040 (disclosed last month), enables full unauthenticated remote code execution (RCE) on vulnerable systems. The vulnerability stems from an unsafe .NET type instantiation issue in SharePoint’s Business Connectivity Services, a component that integrates external data sources. Exploitation grants attackers the privileges of the SharePoint service account, providing deep access to internal infrastructure, document repositories, and connected enterprise applications. Microsoft’s assessment confirms improper input validation as the root cause, making internet-facing or poorly segmented SharePoint servers particularly high-risk targets. Affected systems include all supported versions of Microsoft SharePoint Server, as well as select versions of Microsoft Project Server and Office Web Apps Server, though testing focused primarily on SharePoint. While no active exploitation or public proof-of-concept code exists, Microsoft rates the flaw as "exploitation more likely" due to its potential impact. However, successful attacks require precise technical conditions, as the CVSS scoring indicates high attack complexity. Microsoft has released security updates to address the vulnerability, with patch requirements varying by SharePoint version. Notably, SharePoint Server 2016 and SharePoint Enterprise Server 2016 share the same update package. Organizations are advised to apply all relevant patches immediately, as this marks the second critical SharePoint flaw disclosed from Rapid7’s research in under a month. Rapid7 researcher Stephen Fewer, who discovered the vulnerability, highlighted the importance of chained vulnerability analysis in uncovering deeper architectural weaknesses in enterprise platforms. Security teams are encouraged to audit SharePoint deployments, verify patch levels, and monitor Business Connectivity Services for suspicious activity.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: Microsoft SharePoint Server, Microsoft Project Server, Office Web Apps ServerOperational Impact: Deep access to internal infrastructure, document repositories, and connected enterprise applications
Vulnerability
01 Jul 2026Microsoft_SharePoint
Microsoft: Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild

Critical SharePoint RCE Vulnerability (CVE-2026-50522) Exposes Enterprises to Unauthenticated Attacks

747After Incident
CRITICAL-10
MIC1784643940
Critical SharePoint RCE Vulnerability (CVE-2026-50522) Exposes Enterprises to Unauthenticated Attacks A newly disclosed critical vulnerability, CVE-2026-50522, enables unauthenticated remote code execution (RCE) on on-premises Microsoft SharePoint servers, posing a severe risk to enterprise environments. With a CVSS score of 9.8, the flaw stems from improper deserialization of untrusted data a recurring issue in SharePoint throughout 2026. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition running on x64 deployments. Attackers can exploit it by sending a crafted serialized object to a vulnerable endpoint without authentication or user interaction, leading to arbitrary code execution in the server’s context. Successful exploitation could result in full server takeover, web shell deployment, theft of application secrets, and lateral movement across networks. While Microsoft has not confirmed active exploitation of CVE-2026-50522, its EPSS score of 19.7% indicates a high near-term risk. Researchers at Defused observed undocumented .NET deserialization payloads targeting SharePoint sign-in endpoints in honeypot traffic, suggesting possible exploitation attempts. This activity aligns with CVE-2026-50522 rather than the related CVE-2026-58644, which requires Site Owner permissions and has been confirmed as actively exploited in the wild. Both vulnerabilities were patched in Microsoft’s July 2026 security update, but over 10,000 internet-facing SharePoint servers remain exposed globally, according to Check Point and Censys. Affected versions include: - SharePoint Enterprise Server 2016 (prior to 16.0.5561.1001) - SharePoint Server 2019 (prior to 16.0.10417.20175) - SharePoint Server Subscription Edition (prior to 16.0.19725.20434) Microsoft’s patch must be applied across all SharePoint farm members to prevent exploitation gaps. Organizations are advised to monitor for anomalous unauthenticated requests to authentication endpoints and restrict internet exposure of on-premises SharePoint servers where possible. CVE-2026-58644 has already been added to CISA’s Known Exploited Vulnerabilities catalog, reinforcing the urgency of remediation.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Application secrets, sensitive dataSystems Affected: Microsoft SharePoint serversOperational Impact: Full server takeover, lateral movement across networks
DATA BREACH
Type Of Data Compromised: Application secrets, sensitive dataSensitivity Of Data: High
JUNE 2026
757Before Incident
MAY 2026
760Before Incident
Vulnerability
21 May 2026Microsoft_SharePoint
Microsoft: Microsoft SharePoint Server Vulnerability Enables Remote Code Execution Attacks

Critical SharePoint Server Vulnerability (CVE-2026-45659) Exposes Organizations to Remote Code Execution

756After Incident
CRITICAL-4
MIC1779805440
Critical SharePoint Server Vulnerability (CVE-2026-45659) Exposes Organizations to Remote Code Execution On May 21, 2026, Microsoft disclosed a critical security flaw in SharePoint Server (CVE-2026-45659) that allows authenticated attackers to execute arbitrary code remotely. The vulnerability affects multiple on-premises SharePoint versions, posing a significant risk to organizations using the platform for collaboration and document management. The flaw stems from improper deserialization of untrusted data in Microsoft Office SharePoint, enabling network-based attackers to exploit it with low complexity. Notably, any authenticated user with Site Member-level permissions without requiring administrative access can trigger the vulnerability. Microsoft rated the flaw as Important severity, assessing exploitation as "Less Likely" but warning that its low barrier to entry makes it a serious threat. Affected versions include: - SharePoint Server Subscription Edition (KB 5002863, build 16.0.19725.20280) - SharePoint Server 2019 (KB 5002870, build 16.0.10417.20128) - SharePoint Enterprise Server 2016 (KB 5002868, build 16.0.5552.1002) Microsoft has released patches for all impacted versions. While no active exploitation has been reported, the vulnerability’s network-accessible attack surface and low complexity increase the risk of future exploitation once proof-of-concept code emerges. Organizations are advised to apply updates immediately, audit user permissions, monitor logs for suspicious activity, and isolate internet-facing instances until patches are deployed.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: SharePoint Server (on-premises)
APRIL 2026
765Before Incident
Vulnerability
14 Apr 2026Microsoft_SharePoint
Microsoft: Cyber Security News ®’s Post

Microsoft SharePoint Zero-Day Vulnerability (CVE-2026-32201) Under Active Exploitation

760After Incident
CRITICAL-5
MIC1776227043
Microsoft SharePoint Zero-Day Vulnerability (CVE-2026-32201) Under Active Exploitation On April 14, 2026, Microsoft confirmed the active exploitation of a critical zero-day spoofing vulnerability in SharePoint Server, addressed in its monthly security update. Tracked as CVE-2026-32201, the flaw affects multiple SharePoint Server versions and carries a CVSS base score of 6.5 (Important), with a temporal score of 6.0 following the release of an official patch. The vulnerability stems from improper input validation (CWE-20) in Microsoft Office SharePoint, enabling unauthenticated remote attackers to conduct spoofing attacks over a network. Independent researcher Ronald Lovelace (Cloudy_Day) highlighted systemic issues in Microsoft’s content delivery network (CDN) architecture, linking the flaw to unmitigated misconfigurations first reported in July 2024. Despite CERT’s engagement with Microsoft in January 2025, proof-of-concept files were removed from the Microsoft Security Response Center (MSRC) but remained accessible via obscure portal routes, suggesting concealment rather than resolution. Lovelace’s findings indicate broader risks, including GitHub OAuth flow misconfigurations that expose admin panels, configurations, and unpublished content due to misrouted fallback behavior in Microsoft’s CDN layers. Variations in headers or query parameters can bypass existing protections, posing national security concerns. The issue reflects a pattern of persistent, unaddressed delivery architecture flaws affecting multiple agencies and third-party services. Microsoft has not publicly acknowledged the full scope of the CDN-related risks, despite ongoing exploitation. The vulnerability underscores long-standing security gaps in enterprise collaboration platforms.
INCIDENT DETAILS -
TYPE
Zero-Day Vulnerability
IMPACT
Systems Affected: Microsoft SharePoint ServerOperational Impact: Spoofing attacks, exposure of admin panels and unpublished contentBrand Reputation Impact: Potential national security concerns, systemic security gaps
DATA BREACH
Type Of Data Compromised: Admin panels, configurations, unpublished contentSensitivity Of Data: High (potential national security concerns)
MARCH 2026
769Before Incident
Vulnerability
18 Mar 2026Microsoft_SharePoint
Microsoft: Cyber Security News ®’s Post

CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability (CVE-2026-20963)

764After Incident
CRITICAL-5
MIC1773908622
CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability On March 18, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20963, a critical security flaw in Microsoft SharePoint, to its Known Exploited Vulnerabilities (KEV) catalog. The inclusion confirms that threat actors are actively exploiting the vulnerability in real-world attacks, posing a significant risk to organizations using the collaboration platform. The flaw stems from improper deserialization of untrusted data in SharePoint, allowing attackers to execute arbitrary code or gain unauthorized access. While details on the specific attack vectors remain limited, the urgency of the KEV listing underscores the need for immediate patching or mitigation. Microsoft has not yet disclosed the full scope of affected versions, but network administrators are advised to monitor updates and apply security fixes as they become available. The vulnerability highlights ongoing risks in widely used enterprise software, particularly in platforms handling sensitive data.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: Microsoft SharePoint
FEBRUARY 2026
769Before Incident
JANUARY 2026
769Before Incident
DECEMBER 2025
769Before Incident
NOVEMBER 2025
768Before Incident
OCTOBER 2025
768Before Incident
MAY 2025
769Before Incident
Vulnerability
01 May 2025Microsoft_SharePoint
Microsoft: PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

Critical SharePoint RCE Vulnerability (CVE-2025-53770) Exploited in the Wild

767After Incident
CRITICAL-2
MIC1783520623
Critical SharePoint RCE Vulnerability (CVE-2025-53770) Exploited in the Wild Proof-of-concept (PoC) exploit code and technical details have been released for CVE-2025-53770, a critical remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server. The flaw, a deserialization-of-untrusted-data issue, allows unauthenticated attackers to execute arbitrary code over the network by exploiting how SharePoint processes specially crafted data sources. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition, but Microsoft 365 SharePoint Online remains unaffected. Microsoft initially released emergency patches, followed by a second fix introducing the TypeNameParserImpl component to address generic type handling in DataSet objects. Researchers at Viettel Cyber Security demonstrated how attackers can bypass security controls by abusing XML schema processing in the ExcelDataSet control used by PerformancePoint BI services. The attack targets the BIMonitoringAuthoringService web service at the endpoint `/_vti_bin/PPS/PPSAuthoringService.asmx`, specifically the TestConnection method. By embedding malicious `<xs:import>` and `<xs:include>` elements in an external XSD file, attackers force SharePoint to load unsafe types from an attacker-controlled server, evading XmlValidator checks. The PoC exploits a chain of deserialization gadgets including System.Web.UI.LosFormatter and System.Windows.Data.ObjectDataProvider to achieve RCE. The attack requires only a low-privileged SharePoint site member account and involves crafting a SOAP request to the vulnerable endpoint with a malicious ExcelDataSet payload. Successful exploitation spawns arbitrary processes, such as win32calc.exe, on the target server. Security vendors have confirmed active exploitation in the wild, with reports of large-scale ToolShell attack campaigns targeting unpatched SharePoint environments. The release of detailed exploit techniques is expected to accelerate copycat attacks, increasing the urgency for organizations to apply Microsoft’s latest patches. Additional mitigations include enabling AMSI integration, rotating ASP.NET MachineKey values, and monitoring for suspicious PerformancePoint and ViewState activity.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: Microsoft SharePoint Server 2016, 2019, Subscription EditionOperational Impact: Arbitrary code execution on target servers
JUNE 2012
769Before Incident
Vulnerability
16 Jun 2012Microsoft_SharePoint
Microsoft: Disrupting active exploitation of on-premises SharePoint vulnerabilities

Critical SharePoint Vulnerabilities Exploited by Chinese Threat Actors, Leading to Ransomware Attacks

767After Incident
CRITICAL-2
MIC1768636894
Critical SharePoint Vulnerabilities Exploited by Chinese Threat Actors, Leading to Ransomware Attacks On July 19, 2025, Microsoft disclosed active exploitation of two critical vulnerabilities in on-premises SharePoint servers CVE-2025-49706 (spoofing) and CVE-2025-49704 (remote code execution) which do not affect SharePoint Online. The company released security updates for SharePoint Server 2016, 2019, and Subscription Edition to patch these flaws, along with two additional vulnerabilities (CVE-2025-53770 and CVE-2025-53771), which address related security bypasses. ### Threat Actors & Exploitation Microsoft has observed three Chinese threat groups exploiting these vulnerabilities: - Linen Typhoon (active since 2012, targeting government, defense, and human rights organizations). - Violet Typhoon (active since 2015, focusing on espionage against former military personnel, NGOs, and media). - Storm-2603 (a China-based actor deploying Warlock ransomware since July 18, 2025). Exploitation begins with a POST request to the ToolPane endpoint, allowing attackers to bypass authentication and execute remote code. Successful breaches lead to web shell deployment (e.g., spinstall0.aspx), MachineKey theft, and lateral movement using tools like Mimikatz, PsExec, and Impacket. ### Storm-2603’s Ransomware Attack Chain 1. Initial Access: Exploits SharePoint vulnerabilities to deploy spinstall0.aspx web shells. 2. Discovery: Runs whoami and other commands to enumerate privileges. 3. Persistence: Creates scheduled tasks and manipulates IIS components to load malicious .NET assemblies. 4. Credential Theft: Uses Mimikatz to extract credentials from LSASS memory. 5. Lateral Movement: Leverages PsExec, WMI, and Impacket to spread across networks. 6. Ransomware Deployment: Modifies Group Policy Objects (GPOs) to distribute Warlock ransomware. ### Mitigation & Detection Microsoft urges organizations to: - Apply the latest SharePoint security updates immediately. - Enable Antimalware Scan Interface (AMSI) in Full Mode and deploy Microsoft Defender Antivirus. - Rotate SharePoint ASP.NET machine keys and restart IIS after patching. - Monitor for IOCs, including: - Web shells (spinstall0.aspx, spinstall1.aspx). - Malicious files (IIS_Server_dll.dll, SharpHostInfo.x64.exe). - C2 domains (update[.]updatemicfosoft[.]com, msupdate[.]updatemicfosoft[.]com). - IP addresses (65.38.121[.]198, 131.226.2[.]6). ### Microsoft Defender Protections Microsoft Defender XDR detects and blocks: - Exploitation attempts (Exploit:Script/SuspSignoutReq.A). - Web shell activity (Trojan:PowerShell/MachineKeyFinder.DA!amsi). - Ransomware behavior (Ransomware-linked threat actor detected). Organizations using Microsoft Defender Vulnerability Management or External Attack Surface Management (EASM) can identify exposed SharePoint instances and track remediation efforts. Exploitation activity is expected to increase rapidly, with additional threat actors likely adopting these vulnerabilities. Immediate patching and monitoring are critical to preventing compromise.
INCIDENT DETAILS -
TYPE
RansomwareEspionage
MOTIVATION
Financial gainEspionage
IMPACT
Data Compromised: Credentials, sensitive data via web shells and lateral movementSystems Affected: On-premises SharePoint servers (2016, 2019, Subscription Edition)Operational Impact: Lateral movement, ransomware deployment, potential data exfiltrationIdentity Theft Risk: High (credential theft via Mimikatz)
DATA BREACH
CredentialsSensitive organizational dataSensitivity Of Data: High (credentials, internal communications, proprietary data)Data Encryption: Yes (Warlock ransomware)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Microsoft_SharePoint ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Microsoft_SharePoint's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Microsoft_SharePoint's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Microsoft_SharePoint ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Microsoft_SharePoint's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?