Microsoft SharePoint Patches Fail to Stop Zero-Day Attacks on On-Prem Servers
Updated
Updated · The Register · Aug 6
Microsoft SharePoint Patches Fail to Stop Zero-Day Attacks on On-Prem Servers
2 articles · Updated · The Register · Aug 6
Summary
Microsoft’s fixes for on-premises SharePoint did not fully remediate the vulnerabilities, leaving the software under active zero-day attack.
The failure centers on patching: the earlier updates were insufficient, allowing attackers to keep exploiting exposed SharePoint servers after organizations had applied Microsoft’s fixes.
The issue affects on-prem SharePoint rather than Microsoft’s cloud services, sharpening the risk for enterprises that still run the collaboration platform in their own environments.
The episode adds to pressure on Microsoft’s security response, showing how incomplete remediation can turn a patch cycle into a live exploitation window.