Unpatched Microsoft SharePoint servers have found themselves at the center of a wave of overlapping, simultaneous attacks. Microsoft has confirmed that critical vulnerabilities in on-premises deployments opened the door to multiple threat actors operating in parallel — a development that has put CISOs and IT security leaders on high alert worldwide.
The Vulnerabilities Behind the SharePoint Attacks
The CVEs at the Eye of the Storm
Three vulnerabilities made this attack wave possible. The primary flaws are CVE-2025-53770, CVE-2025-49704, and CVE-2025-49706 — all affecting Microsoft SharePoint Server on-premises deployments. Each enables unauthenticated remote code execution (RCE), making them exceptionally dangerous in exposed environments.
CVE-2025-53770, in particular, was classified as an actively exploited zero-day. Attackers leveraged this flaw to compromise systems before defenders had any opportunity to act, leaving targeted organizations with virtually no window for preventive response.
The Scale of Global Exposure
Researchers identified more than 1,300 vulnerable SharePoint servers directly reachable from the public internet at the time of discovery — an easily scannable attack surface for any motivated threat actor.
U.S. government agencies were among those affected. CyberScoop reported approximately 400 organizations compromised, including public-sector entities in the United States. The true scope of the campaign, however, may be considerably broader.
Who Attacked and How
Multiple Actors, Overlapping Campaigns
One of the most alarming aspects of this incident is the sheer number of distinct threat actors involved. Microsoft detected that different groups exploited the same vulnerabilities concurrently — a phenomenon sometimes called a “pile-on attack,” which dramatically complicates incident response efforts.
Some actors appeared to be motivated by espionage objectives, while others pursued financial gain through ransomware deployment or data theft. Affected organizations were simultaneously facing entirely different types of threats, with no clear single adversary to track.
Palo Alto Networks’ Unit 42 conducted an in-depth analysis of the techniques observed. Researchers documented sophisticated exploit chains in which attackers first secured initial access, then moved laterally through the victim’s internal network.
The Attack Chain
The typical attack followed a consistent pattern:
- RCE vulnerability exploitation to gain initial access
- Webshell deployment to establish persistence on the compromised server
- Lateral movement toward other internal systems
- Data exfiltration or delivery of additional malicious payloads
Worth noting is the speed at which all of this unfolded — in many cases, the entire sequence took just minutes, leaving security teams with little to no time to mount a meaningful response.
Microsoft’s Response and Official Guidance
Mitigation Measures
Microsoft addressed the situation in a security blog post published on July 22, 2025, outlining the steps taken to “disrupt active exploitation” of the vulnerabilities. Security updates were released for all affected versions of SharePoint Server.
Microsoft also coordinated with international authorities. Agencies including the Cyber Security Agency of Singapore (CSA) and the Canadian Centre for Cyber Security issued urgent advisories urging organizations to apply the available patches without delay.
Recommendations for Security Leaders
Applying the patch alone, however, is not sufficient. Security teams must also determine whether their systems were already compromised prior to the update being applied. Microsoft strongly recommends conducting active threat hunting across SharePoint server logs.
Key operational guidance includes:
- Apply Microsoft’s security updates immediately
- Isolate any internet-facing SharePoint servers until fully patched
- Review logs for indicators of compromise (IoCs)
- Monitor for anomalous traffic to and from SharePoint servers
- Verify the integrity of system files on affected servers
Beyond these immediate steps, organizations should take this incident as a prompt to revisit their update policies for on-premises infrastructure. Unpatched SharePoint servers represent a structural risk — not a one-off anomaly.
Conclusion
This episode reinforces a deeply concerning trend: critical vulnerabilities in on-premises systems are being weaponized faster than ever, and threat actors are increasingly operating in parallel against the same targets.
For security leaders, the message could not be clearer. There is no longer a grace period between vulnerability disclosure and active exploitation. Keeping Microsoft SharePoint servers up to date is not optional — it is an absolute priority.
Sources:
- CSOonline – Unpatched SharePoint servers opened the door to multiple attackers
- CybersecurityDive – What we know about Microsoft SharePoint attacks
- Unit 42 – CVE-2025-49704, CVE-2025-49706, CVE-2025-53770
- Microsoft Security Blog – Disrupting active exploitation
- CSA Singapore – AL-2025-075
- Canadian Centre for Cyber Security – AL25-009
- CyberScoop – Microsoft SharePoint attacks, 400 victims
The simultaneous, overlapping attacks on SharePoint servers are a stark reminder of how critical timely threat intelligence sharing is among organizations operating in the same sector. IsacChain enables the secure, verified sharing of IoCs and TTPs in real time, while also supporting automated NIS2 compliance through documented, auditable workflows. Blockchain-based verification guarantees the integrity and provenance of every shared indicator, significantly reducing the risk of manipulated or unreliable intelligence. Discover how IsacChain can help your organization at www.isacchain.com