Microsoft SharePoint Flaw Under Active Attack After Exploit Code Goes Public
Microsoft issued a patch in July for a vulnerability affecting SharePoint, its widely used document collaboration platform. At the time, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that the flaw could attract real-world attackers, and that warning has now proven accurate.
Shortly after proof-of-concept (PoC) exploit code for the vulnerability was released publicly, security researchers observed active exploitation attempts against unpatched systems. This is a common and predictable pattern in cybersecurity: once technical details or working exploit code for a vulnerability become public, attackers move quickly to weaponise them before organisations have applied fixes.
For Australian small and medium businesses, this incident is a reminder that patches are only effective once installed. Many businesses run SharePoint either on-premises or through Microsoft 365 environments to manage documents and internal collaboration, making it an attractive target. Delayed patching, especially for internet-facing systems, significantly widens the window of opportunity for attackers.