The tech giant’s Security Response Center reported coordinated attacks targeting internet-facing SharePoint installations using newly disclosed vulnerabilities that enable authentication bypass and remote code execution. Microsoft has released critical security updates for all supported SharePoint versions, including KB5002768 for SharePoint Server Subscription Edition, KB5002754 and KB5002753 for SharePoint 2019, and KB5002760 and KB5002759 for SharePoint 2016. These vulnerabilities specifically target on-premises SharePoint Server installations, including SharePoint Server 2016, 2019, and SharePoint Subscription Edition, while SharePoint Online in Microsoft 365 remains unaffected. The exploitation campaign centers around CVE-2025-53770, a comprehensive vulnerability that combines authentication bypass and remote code execution capabilities, alongside CVE-2025-53771, which addresses security bypass issues related to the previously disclosed CVE-2025-49706. Microsoft strongly recommends deploying Microsoft Defender for Endpoint or equivalent solutions to detect post-exploitation activities and considering temporary disconnection from internet access for unpatched systems until security updates can be applied.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 23 Jul 2025 05:45:06 +0000