Hackers are actively exploiting security flaws in on-premises Microsoft SharePoint Server, according to a fresh warning from the US Cybersecurity and Infrastructure Security Agency (CISA). If your business runs SharePoint on its own servers rather than through Microsoft 365, this needs immediate attention.
- What it is: Four vulnerabilities in SharePoint Server (2016, 2019, and Subscription Edition) are being used together by attackers to break in, run malicious code, and steal server credentials.
- Who is affected: Organisations running on-premises SharePoint Server. This does not affect SharePoint Online included with Microsoft 365, which Microsoft manages and patches automatically.
- The risk: Successful attacks give hackers remote access to the server and a foothold to move further into the network, steal data, or deploy ransomware.
- What to do: Microsoft has released patches for all four vulnerabilities. If you run on-premises SharePoint, these updates should be applied as a priority, not on the normal patching schedule.
We recommend any business still running on-premises SharePoint confirm with their IT provider that these patches are installed. If you are unsure whether this applies to your environment, get in touch and we will check for you.