logo

SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency

ID: a8565b2c-f462-5f04-b51e-b14897a14833

STIX ID: report--a8565b2c-f462-5f04-b51e-b14897a14833

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

Author: Pierluigi Paganini

...
...

Swiss Federal IT Agency FOITT disclosed that unknown attackers exploited recently disclosed Microsoft SharePoint vulnerabilities (including CVE-2026-50522, CVSS 9.8) to compromise about 200 user and technical accounts on on-premises SharePoint servers; FOITT blocked external access, began patching, reset credentials, and is reinstalling affected servers as investigations with NCSC and Microsoft continue. The report warns that theft of machine keys allows forging of legitimate requests and persistent access, recommends applying July patches, rotating machine keys and restarting IIS, and cautions against directly exposing SharePoint servers to the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.