New zero-day bug in Microsoft SharePoint under widespread attack
ID: cb66cbeb-e5c0-566e-8372-1c636ee95ff3
STIX ID: report--cb66cbeb-e5c0-566e-8372-1c636ee95ff3
Feed Name: TechCrunch Security News
A newly disclosed zero-day vulnerability in on-premises Microsoft SharePoint (CVE-2025-53770) is being actively exploited in the wild, allowing attackers to steal private digital keys, impersonate legitimate requests, deploy malware, and access stored files. CISA issued an alert after security researchers (Eye Security) found dozens of actively exploited servers; Microsoft is developing patches for affected versions including SharePoint Server 2016, and impacted organizations — including U.S. federal agencies, universities, and energy companies — are urged to take immediate actions such as disconnecting exposed systems and rotating keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
