Microsoft Warns of Active Zero-Day SharePoint Exploit Affecting 75+ Companies

TL;DR Summary
Microsoft SharePoint servers are currently under a widespread attack exploiting a critical vulnerability (CVE-2025-53770) with no available patch, allowing attackers to gain control without authentication, potentially leading to data theft and lateral movement across networks. Microsoft is working on a fix, and users are advised to implement mitigations such as enabling antimalware and disconnecting servers from the internet if possible.
- Microsoft Confirms Ongoing Mass SharePoint Attack — No Patch Available Forbes
- Global hack on Microsoft product hits U.S., state agencies, researchers say The Washington Post
- Microsoft alerts businesses, governments to server software attack Reuters
- Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company Servers The Hacker News
- Microsoft SharePoint servers under attack via zero-day vulnerability with no patch (CVE-2025-53770) Help Net Security
Reading Insights
Total Reads
0
Unique Readers
0
Time Saved
2 min
vs 3 min read
Condensed
89%
555 → 60 words
Want the full story? Read the original article
Read on Forbes