Web_Logo
Remote Support
Security Alert: On-Premises SharePoint Under Active Attack
Home » Security Alerts  »  Security Alert: On-Premises SharePoint Under Active Attack

Security Alert: On-Premises SharePoint Under Active Attack

US cybersecurity authorities have issued an urgent warning that hackers are actively breaking into on-premises Microsoft SharePoint servers, stealing data and installing malware that can survive a normal software patch.

  • What it is: Attackers are exploiting several security flaws in SharePoint Server (the version installed on your own hardware, not SharePoint Online in Microsoft 365) to gain full access without needing a password.
  • Who is affected: Only organisations running an on-premises SharePoint Server (2016, 2019, or Subscription Edition). SharePoint Online, included with Microsoft 365, is not affected.
  • The risk: Once inside, attackers can steal sensitive files, harvest login credentials, and plant malware that keeps working even after the official patch is applied, because it hides in the server's encryption keys.
  • What to do: Apply Microsoft's latest SharePoint security updates immediately, and have your IT provider check the server for signs of prior compromise, since patching alone will not remove an existing infection.

If your business runs an on-premises SharePoint server, we recommend treating this as urgent and arranging a compromise check alongside the patch. Source: CISA advisory.