FILE - The Microsoft logo is seen at its office in Sydney, Australia. (AP Photo/Rick Rycroft, File)



Microsoft has rolled out an urgent security fix to stop hackers from exploiting a dangerous vulnerability in its SharePoint software. This flaw has already been used to launch cyberattacks on several businesses and even some federal agencies. The threat, identified as a zero-day vulnerability, is being actively targeted by cybercriminals, making immediate action critical.

Over the weekend, Microsoft notified users about the issue and released specific guidance to address the problem in SharePoint Server 2019 and the SharePoint Server Subscription Edition. Engineers are still working on a solution for the older SharePoint Server 2016.

What’s a Zero-Day Exploit, and Why Is It Serious?

A zero-day exploit is a type of cyberattack that takes advantage of a security flaw before developers even know it exists. The term “zero-day” means that defenders have zero days to fix it once it’s discovered.

According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the current exploit is a variant of an existing vulnerability labeled CVE-2025-49706. The bug poses a significant threat to organizations using on-site SharePoint servers.

Cybersecurity experts have dubbed the exploit “ToolShell.” This tool can potentially give attackers full access to SharePoint’s file systems. Even services linked to SharePoint—like Microsoft Teams and OneDrive—can be affected, allowing hackers to move across systems with ease.

Perhaps more troubling, Google’s Threat Intelligence Group warns that this vulnerability may let attackers bypass future security updates as well, making it even harder to stop them once they’ve gained access.

How Far Has the Damage Spread?

In a blog post, cybersecurity firm Eye Security revealed that it scanned more than 8,000 SharePoint servers across the globe. Dozens of these were already compromised, and the attacks likely began on July 18.

While it’s too early to know the full extent of the damage, CISA has advised that any affected servers should be taken offline immediately until proper patches are installed. The agency is treating the situation as a high-level threat due to the scale and speed of the attacks.

Organizations relying on SharePoint for file storage, internal communication, or cloud services need to act fast. If unpatched, this flaw could leave sensitive information wide open to cybercriminals.

What Should Users Do Now?

If your organization uses SharePoint Server 2019 or the Subscription Edition, follow Microsoft’s latest patch instructions immediately. If you’re still running SharePoint Server 2016, stay alert for updates and take preventive steps like temporarily removing internet access to your servers.

This vulnerability is a strong reminder that staying up to date with security patches isn't just good practice—it’s essential.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

China Economic Growth Target 2026 Set at 4.5%–5% Amid Rising Challenges

China has set a lower economic growth target for 2026, signaling a cautious approach as domestic pressures and global uncertainty....

Newfoundland and Labrador Hydro Addresses Major Island-Wide Outage

A sudden and widespread power disruption left much of the island without electricity Thursday afternoon, prompting Newfoundland and Labrador Hydro....

Netflix Warner Deal Collapses as Paramount Moves Closer to Takeover

Netflix has stepped away from the race to acquire Warner Bros. Discovery, clearing a potential path for Paramount to take....

NVIDIA Financial Results Power Record-Breaking Fiscal 2026 Performance

NVIDIA's financial results for the fourth quarter of fiscal 2026 have set a new benchmark for the semiconductor industry, as....

Transport Canada Certifies Gulfstream G500 and G600 Jets Amid U.S. Pressure

Canada has officially approved two major business aircraft models after weeks of political tension and regulatory scrutiny.The decision confirms that....

Reese’s Peanut Butter Cups Quality Row: Inventor’s Grandson Targets Hershey

A family dispute has erupted over the famous Reese’s Peanut Butter Cups recipe and brand quality.Brad Reese, grandson of inventor....

Nutritious Starbucks Foods: Dietitian Shares Smart, Balanced Menu Picks

Many customers walk into Starbucks looking for quick coffee and convenient meals, yet not every option supports balanced nutrition. While....

TELUS CEO Transition: Darren Entwistle to Retire, Victor Dodig Named Successor

TELUS CEO transition plans are now officially in motion as Darren Entwistle prepares to retire after more than 26 years....

Costco Minimum Wage Rises to $21 as Retail Pay Pressure Builds

Costco is reinforcing its reputation as a high-paying retailer with a fresh wage increase.The company has confirmed that its minimum....

Stellantis Stake in Ontario Battery Factory Sold to LG Energy Solution

Stellantis has decided to exit its ownership role in a major Canadian battery project.The automaker will sell its stake in....

Google AI Growth Surges as Alphabet Overtakes OpenAI in the Race for Leadership

Alphabet has staged a sharp turnaround in artificial intelligence.Once seen as lagging rivals, Google now leads the AI conversation.Investors who....

Toys “R” Us Canada Creditor Protection: Retailer Seeks Relief Amid $120M Debt

Toys “R” Us Canada has taken a major step to survive mounting financial pressure.The iconic toy retailer has filed for....