Skip to content

Microsoft's SharePoint Breached Worldwide: Critical Vulnerability Exploited

Your data may be at risk. Microsoft's SharePoint has been breached globally due to a critical vulnerability. Patch now to protect your systems.

In the image there are few people, the first two men were wearing Microsoft id cards.
In the image there are few people, the first two men were wearing Microsoft id cards.

Microsoft's SharePoint Breached Worldwide: Critical Vulnerability Exploited

Hackers have exploited a critical vulnerability in Microsoft 365's SharePoint software, breaching governments, businesses, and organizations worldwide. The attacks, which began mid-2025, have compromised sign-in credentials and drawn scrutiny to Microsoft 365's cybersecurity efforts.

The cybersecurity firm Outsidersecurity discovered the SharePoint zero-day vulnerability, dubbed 'ToolShell' (CVE-2025-53770), which allowed hackers to gain unauthorized access to systems. The German Federal Office for Information Security (BSI) classified the threat level as critical. Multiple hackers, including those tracked by CrowdStrike and Google's Mandiant Consulting, have launched attacks through this vulnerability.

Microsoft has released a patch for the server-side issue but is still working on fixes for clients. However, Eye Security warns that hackers can maintain access through backdoors or modified components even after patches are applied. The US has the largest number of companies at risk, with over 10,000 firms running SharePoint servers vulnerable to attack.

The breaches have affected national governments in Europe and the Middle East, as well as US government systems like the Department of Education, Florida's Department of Revenue, and the Rhode Island General Assembly. Private entities, including a US-based health-care provider and a public university in Southeast Asia, have also been targeted. Attempts have been made in countries such as Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK, and the US.

Microsoft is actively working to address the SharePoint vulnerability and protect its clients. However, the recent breaches have raised concerns about Microsoft 365's cybersecurity measures. As investigations continue, organizations are urged to apply the available patches and remain vigilant against potential threats.

Read also:

Latest