Microsoft Warns of Ongoing Zero-Day Attacks on SharePoint Servers Targeting Businesses and Government Agencies

Zero-Day Exploit Puts Thousands of SharePoint Servers at Risk as Microsoft, FBI, and Cybersecurity Agencies Urge Immediate Action to Prevent Spoofing Attacks


FBI, CISA, and Microsoft issue urgent alerts as threat actors exploit critical SharePoint vulnerability in on-premise servers—cloud users remain unaffected


In a serious escalation of global cybersecurity threats, Microsoft has issued an urgent security alert warning of “active attacks” targeting on-premise SharePoint servers used by government agencies and businesses for internal document sharing. The zero-day vulnerability, now being actively exploited, does not affect SharePoint Online in Microsoft 365, the company confirmed.

The Federal Bureau of Investigation (FBI) acknowledged it is aware of the attacks and is working alongside federal and private sector partners to respond, though it did not release additional information at this time.

According to Microsoft’s statement, the vulnerability allows authorized attackers to carry out spoofing over a network, posing as trusted users, systems, or websites to manipulate access and potentially sensitive operations. Spoofing is especially dangerous in government or financial settings, where impersonation can lead to significant breaches and operational disruptions.

The attacks were first reported by The Washington Post, which described the incident as a zero-day exploit—a reference to the fact that the vulnerability was previously unknown to software developers, giving attackers a window of opportunity with no existing defense. Experts cited in the report warned that tens of thousands of on-premise SharePoint servers globally could be at risk.

Microsoft, in coordination with CISA (Cybersecurity and Infrastructure Security Agency), the Department of Defense Cyber Defense Command, and other global cybersecurity agencies, has rolled out immediate security updates and is urging affected organizations to install them without delay.

For organizations running SharePoint 2016 and 2019, Microsoft is currently developing additional security updates. In the interim, companies unable to apply malware protections are strongly advised to disconnect their SharePoint servers from the internet to minimize exposure until patches are available.

We’ve been coordinating closely with CISA, DOD Cyber Defense Command and key cybersecurity partners globally throughout our response,” a Microsoft spokesperson emphasized, highlighting the collaborative approach being taken to contain the threat.

The incident underscores the critical importance of timely security patching and monitoring of enterprise infrastructure, particularly in sectors reliant on on-premise software solutions.


Key Recommendations for SharePoint Server Users:

  • Install Microsoft’s latest security updates immediately
  • Disconnect vulnerable servers from the internet if patching isn’t possible
  • Monitor network activity for signs of spoofing or unauthorized access
  • Transition to cloud-based solutions like SharePoint Online when feasible for enhanced protection

As cyber threats grow in complexity and scale, this latest attack serves as a wake-up call for enterprises worldwide to proactively defend against evolving digital risks.

Manish Singh

Manish Singh is the visionary Editor of CEO Times, where he curates and crafts the stories of the world’s most dynamic entrepreneurs, executives, and innovators. Known for building one of the fastest-growing media networks, Manish has redefined modern publishing through his sharp editorial direction and global influence. As the founder of over 50+ niche magazine brands—including Dubai Magazine, Hollywood Magazine, and CEO Los Angeles—he continues to spotlight emerging leaders and legacy-makers across industries.

Previous Story

Unlocking Capital with Precision: How Zac Safron and Levered Up Are Redefining Business Funding

Next Story

Astronomer CEO Placed on Leave After Viral Coldplay ‘Jumbotron’ Moment Sparks Internet Frenzy

Latest from Business