logo

Microsoft patches critical SharePoint 2016 zero-days amid active exploits

ID: 63daee82-b9b3-5063-82b0-0dc2ae4bbcb8

STIX ID: report--63daee82-b9b3-5063-82b0-0dc2ae4bbcb8

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-07-22

Date Updated: 2026-04-26

Author: Richard Speed

...
...

Microsoft released emergency patches for two actively exploited zero-day vulnerabilities in on‑premises SharePoint Server (CVE-2025-53770 and CVE-2025-53771) after reports that attackers were accessing and exfiltrating data from vulnerable servers — potentially thousands of instances including some US government systems. Because attackers could have stolen keys and retained access even after patching, Microsoft and researchers advise administrators to apply updates, rotate ASP.NET machine keys, restart IIS, and use detection tools (e.g., Defender for Endpoint, AMSI full mode) while investigating possible intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.