Microsoft patches critical SharePoint 2016 zero-days amid active exploits
ID: 63daee82-b9b3-5063-82b0-0dc2ae4bbcb8
STIX ID: report--63daee82-b9b3-5063-82b0-0dc2ae4bbcb8
Feed Name: The Register (Security)
Microsoft released emergency patches for two actively exploited zero-day vulnerabilities in on‑premises SharePoint Server (CVE-2025-53770 and CVE-2025-53771) after reports that attackers were accessing and exfiltrating data from vulnerable servers — potentially thousands of instances including some US government systems. Because attackers could have stolen keys and retained access even after patching, Microsoft and researchers advise administrators to apply updates, rotate ASP.NET machine keys, restart IIS, and use detection tools (e.g., Defender for Endpoint, AMSI full mode) while investigating possible intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
