SharePoint vulnerability with 9.8 severity rating under exploit across globe

SharePoint vulnerability with 9.8 severity rating under exploit across globe

A troubling new vulnerability in Microsoft SharePoint Server has emerged, prompting urgent warnings from authorities and cybersecurity experts. This critical flaw, identified as CVE-2025-53770, boasts a severity rating of 9.8 out of 10, making it a prime target for cybercriminals seeking to exploit sensitive company information, including vital authentication tokens that grant access to internal systems. Experts have advised that any organization operating an on-premises version of SharePoint should treat their networks as compromised. The vulnerability allows unauthorized remote access to SharePoint Servers that are publicly exposed on the Internet. Reports of mass exploitation began circulating on Friday, highlighting the serious threat to those utilizing in-house infrastructure. Notably, Microsoft’s cloud-based SharePoint Online and Microsoft 365 remain unaffected by this issue. On Saturday, Microsoft confirmed the existence of active attacks exploiting this zero-day vulnerability. In a timely response, the company released an emergency update the following day to address this flaw and a related vulnerability, CVE-2025-53771, affecting both SharePoint Subscription Edition and SharePoint 2019. Users of these versions are urged to implement the updates without delay, as SharePoint 2016 remained unpatched at the time of reporting. For those still using SharePoint 2016, Microsoft has recommended the installation of the Antimalware Scam Interface to bolster defenses. Interestingly, the exploitation methods observed are reminiscent of techniques demonstrated earlier this year at the Pwn2Own hacking competition in Berlin, targeting two separate vulnerabilities, CVE-2025-49704 and CVE-2025-49706, which were partially patched in a previous monthly update. The latest patches for CVE-2025-53770 and CVE-2025-53771 promise enhanced protections against the previously exploited vulnerabilities, underscoring the urgency for all affected users to act swiftly.

Sources : Ars Technica

Published On : Jul 21, 2025, 19:35

AI
AI Impact on Job Market: A Complex Picture Unfolds

Concerns about job losses due to artificial intelligence are escalating as more companies announce layoffs. As of May 20...

TechCrunch | Jun 30, 2026, 04:10
AI Impact on Job Market: A Complex Picture Unfolds
Computing
Memory Chip Crisis Deepens Amid AI Data Center Expansion

The ongoing memory chip shortage, which has significantly contributed to rising prices for consumer electronics, shows n...

Business Insider | Jun 30, 2026, 09:40
Memory Chip Crisis Deepens Amid AI Data Center Expansion
Startups
VaSi: A Revolutionary AI Learning Platform Launched by Vandana Sikka

A groundbreaking new platform named VaSi has emerged, designed to empower individuals to share their expertise through l...

Business Today | Jun 30, 2026, 08:20
VaSi: A Revolutionary AI Learning Platform Launched by Vandana Sikka
AI
Meta Tightens Access to Rival AI Tools Amid Intellectual Property Concerns

Meta has taken the significant step of limiting employee access to artificial intelligence tools developed by competitor...

Business Today | Jun 30, 2026, 07:25
Meta Tightens Access to Rival AI Tools Amid Intellectual Property Concerns
Mobile
Unlocking Privacy: How to Secure Your WhatsApp Username

WhatsApp is set to introduce a game-changing feature: the ability to reserve a unique username, enhancing user privacy b...

Business Today | Jun 30, 2026, 06:35
Unlocking Privacy: How to Secure Your WhatsApp Username
View All News