Microsoft has issued a patch for a critical vulnerability affecting sharepoint Server 2016, an on-premises data center solution.The exploit, identified as CVE-2025-53770, has been actively exploited in the wild, according to Palo alto Networks researchers, who estimate that thousands of organizations globally may have been impacted.
Palo Alto Networks stated that the exploits are “real” and pose a “serious threat.” Microsoft confirmed the attack targets on-premises SharePoint servers but not cloud-based versions like Microsoft 365. SharePoint is widely used by businesses for document storage and collaboration.
European cybersecurity firm Eye Security,which first identified the flaw,noted that the vulnerability is notably concerning as it allows attackers to impersonate users or services even after a server has been patched. given that SharePoint servers often integrate with other Microsoft services such as Outlook and Teams, a breach could rapidly lead to data theft and password harvesting.
Michael Sikorski, CTO and head of threat intelligence for Palo Alto’s Unit 42, elaborated that attackers are exfiltrating sensitive data, deploying persistent backdoors, and stealing cryptographic keys. he added,”The attackers have leveraged this vulnerability to get into systems and are already establishing their foothold.”
In a separate incident, Alaska Airlines temporarily suspended its ground operations for approximately three hours on Sunday due to an IT outage. The airline lifted the ground stop around 2 a.m. EST. It remains unclear if this outage is connected to the SharePoint vulnerability.