Microsoft has issued an urgent security alert warning businesses, government agencies, and international organisations of ongoing “active attacks” targeting on-premises SharePoint servers. The technology giant urged customers to immediately apply security updates to prevent further exploitation of the vulnerabilities, which have already been used in zero-day attacks over recent days.
The Federal Bureau of Investigation (FBI) confirmed on Sunday that it is monitoring the situation closely and coordinating with federal and private-sector partners, but declined to share further operational details.
Cloud Services Not Impacted
In a security advisory issued on Saturday, Microsoft emphasized that the attacks are limited to on-premises SharePoint servers. Its cloud-based service, SharePoint Online in Microsoft 365, has not been affected.
The attacks, first reported by The Washington Post, involve unidentified threat actors exploiting a previously unknown zero-day vulnerability. Cybersecurity experts cited by the newspaper warned that tens of thousands of servers could be at risk if organisations fail to take swift action.
Microsoft identified the exploited vulnerabilities as CVE-2025-53770 and CVE-2025-53771, both of which affect supported on-premises SharePoint Server versions. Attackers have been able to use the flaws to conduct spoofing attacks, where malicious actors disguise themselves as trusted individuals, organisations, or websites.
Such spoofing techniques can enable attackers to manipulate financial markets, compromise sensitive communications, or gain unauthorised access to secure networks, Microsoft warned.
Security Updates Released
Microsoft has now released patches designed to close these vulnerabilities for SharePoint Server Subscription Edition and SharePoint Server 2019, while security fixes for SharePoint Server 2016 remain under development.
Available Security Updates:
The company’s security team is continuing to develop patches for older versions and recommends that organisations unable to immediately apply updates disconnect their SharePoint servers from the internet as a temporary safeguard.
Additional Security Guidance
In its latest Customer Guidance for SharePoint Vulnerability CVE-2025-53770, published July 19 and updated July 20 and 21, Microsoft laid out a series of defensive measures:
-
Upgrade to supported versions of on-premises SharePoint (2016, 2019, or Subscription Edition).
-
Apply the July 2025 Security Update without delay.
-
Enable and correctly configure the Antimalware Scan Interface (AMSI) with solutions like Microsoft Defender Antivirus.
-
Deploy Microsoft Defender for Endpoint or similar enterprise-level threat detection systems.
-
Rotate ASP.NET machine keys to prevent further exploitation.
The company also updated Microsoft Defender detections and protections, including new MDE alerts and vulnerability mapping capabilities, to help organisations identify compromised systems and mitigate further attacks.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- Half of SMEs Struggle to Keep Up With Security Threats
- 1 in 4 SMEs Find Remote Working A Key Cybersecurity Concern
FBI and Microsoft Coordinate Global Response
The FBI’s involvement underscores the potential scale and seriousness of the attacks, which have already targeted a mix of U.S. and international agencies as well as private businesses. Microsoft said it has been working in tandem with global cybersecurity partners to ensure a rapid and coordinated response.
The company confirmed that its initial July security update only partially addressed the vulnerabilities, but the newly released patches for SharePoint Subscription Edition and SharePoint 2019 now provide full protection. It advised all customers to monitor its official Microsoft Security Response Center (MSRC) blog for updates, particularly for SharePoint 2016 users still awaiting a final patch.





