A 0-day flaw in Microsoft SharePoint is being exploited in RCE attacks on servers globally; no patch exists and tens of thousands of servers are at risk
A 0-day flaw in Microsoft SharePoint is being exploited in RCE attacks on servers globally; no patch exists and tens of thousands of servers are at risk

research.eye.security
SharePoint 0-day uncovered (CVE-2025-53770)

First time ever that’s happened.
. . . right?
Sharepoint is in fuckin everything now so this is probably gonna be a fun one.
These CVEs are only for On-Prem Sharepoint. Not Office/Microsoft 365 Sharepoint, which is the cloud based one integrated into Teams, underlying behind Onedrive, etc.
So not as chaotic or wide reaching as you might be thinking.