Microsoft Warns SharePoint Zero-Day Attack Persists After 2 Failed Patches
Updated
Updated · The Register · Aug 31
Microsoft Warns SharePoint Zero-Day Attack Persists After 2 Failed Patches
3 articles · Updated · The Register · Aug 31
Summary
On-premises SharePoint is under active zero-day attack after Microsoft said earlier fixes did not fully close the vulnerabilities.
Two failed patches left exposed systems still vulnerable, turning what should have been a routine remediation into an ongoing security incident.
Microsoft’s warning applies specifically to on-prem SharePoint deployments rather than its cloud services, narrowing the immediate risk to self-managed enterprise servers.
The episode underscores a familiar security pattern: incomplete fixes can extend attackers’ window and force organizations into repeated emergency patching.