Microsoft Warns Of Active Exploits Targeting SharePoint Vulnerabilities

Microsoft Corp (NASDAQ:MSFT) has issued a critical warning regarding ongoing attacks on on-premises SharePoint servers, urging organizations to apply newly released security updates immediately.

The alert, published July 19 by the Microsoft Security Response Center, highlights active exploitation of two key vulnerabilities—a spoofing flaw and a remote code execution flaw—by state-linked threat actors.

These vulnerabilities do not impact SharePoint Online hosted on Microsoft 365.

The new updates cover supported versions of SharePoint Server, including Subscription Edition, 2019, and 2016.

Also Read: Microsoft Raids Google DeepMind To Supercharge AI Copilot, Even As Redmond Cuts 9,000 Jobs Elsewhere: Report

Microsoft emphasized that the patches also address additional related flaws—CVE-2025-53770 and a bypass vulnerability CVE-2025-53771—providing a more comprehensive security fix.

Microsoft attributed the exploitation campaigns to three China-based threat actors: Linen Typhoon, Violet Typhoon, and Storm-2603.

According to the company, these ...