Microsoft (MSFT) said in a statement: “On July 19, 2025, Microsoft Security Response Center published a blog addressing active attacks against on-premises SharePoint servers that exploit CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability. These vulnerabilities affect on-premises SharePoint servers only and do not affect SharePoint Online in Microsoft 365. Microsoft has released new comprehensive security updates for all supported versions of SharePoint Server that protect customers against these new vulnerabilities. Customers should apply these updates immediately to ensure they are protected. These comprehensive security updates address newly disclosed security vulnerabilities in CVE-2025-53770 that are related to the previously disclosed vulnerability CVE-2025-49704. The updates also address the security bypass vulnerability CVE-2025-53771 for the previously disclosed CVE-2025-49706. As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint servers. In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities. Investigations into other actors also using these exploits are still ongoing. With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems. This blog shares details of observed exploitation of CVE-2025-49706 and CVE-2025-49704 and the follow-on tactics, techniques, and procedures by threat actors. We will update this blog with more information as our investigation continues.”
Elevate Your Investing Strategy:
- Take advantage of TipRanks Premium at 50% off! Unlock powerful investing tools, advanced data, and expert analyst insights to help you invest with confidence.
Published first on TheFly – the ultimate source for real-time, market-moving breaking financial news. Try Now>>
Read More on MSFT:
- Quantum Computing News: D-Wave (QBTS) Targets $5M ROI, BofA Sees Breakthrough Potential, JPM Overhauls Research Leadership
- Microsoft price target raised to $613 from $605 at Citi
- Microsoft’s Strong Performance and Future Potential Highlighted by Analyst Tyler Radke
- Microsoft works to stop hackers using SharePoint exploit, Bloomberg says
- Microsoft’s Strong Growth Potential and Attractive Valuation Highlighted by Analyst Keith Weiss