Microsoft warns of severe security vulnerability in SharePoint – Tens of thousands of companies affected

Microsoft warns of severe SharePoint hack – tens of thousands of companies and institutions worldwide are affected by attacks.

7/22/2025, 12:12 PM
Eulerpool News Jul 22, 2025, 12:12 PM

Microsoft has issued an acute security warning for its widely used document management software SharePoint. Hackers are currently exploiting vulnerabilities to gain access to file systems and execute malicious code. According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), there is a risk of serious global security incidents.

Particularly affected are companies that operate SharePoint servers themselves and do not host via Microsoft's cloud services. According to Microsoft, an emergency patch was released over the weekend, but further security updates are in progress. Security researchers warn that potentially tens of thousands of organizations are at risk.

The US security provider Censys estimates that worldwide more than 10,000 companies are working with vulnerable SharePoint instances. Most of them are located in the US, followed by the Netherlands, the UK, and Canada. "For ransomware actors, this is a dream. Many attackers will work through the weekend," said Silas Cutler of Censys.

Palo Alto Networks and Google's Threat Intelligence Group also classify the threat as acute. Google warned that the vulnerability allows persistent, unauthenticated access, posing a significant risk. According to Blackpanda CEO Gene Yu, a compromised SharePoint server can have far-reaching consequences: "If you crack this bastion, everything is in the hands of the attackers.

The vulnerability was initially discovered by Dutch Eye Security. Through this gap, attackers could steal so-called keys, allowing them to continue posing as legitimate users or services even after a patch. Even after updates or reboots, hackers could retain access through backdoors or manipulated components.

According to reports from the Washington Post, in addition to US agencies, universities, energy companies, and an Asian telecommunications provider are also affected by the attacks.

Microsoft has been under pressure for years due to numerous security incidents.

Discover undervalued stocks with Eulerpool.

News