SharePoint attacks put unpatched and end-of-life servers at risk
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 25th, 2026.
Active exploitation is targeting a Microsoft SharePoint Server weakness that can let an authenticated attacker execute code. When it’s chained with other SharePoint weaknesses, it can reportedly enable remote code execution before authentication on servers configured to permit anonymous access. Organizations that haven’t applied earlier SharePoint security updates face greater exposure because the attack can rely on more than one weakness.
A compromised collaboration server could expose internal documents, identities and trusted business workflows. There’s also a lifecycle problem. SharePoint Enterprise Server 2016 and Server 2019 reached end of life on July 15th, 2026, so migration now forms part of the security response. Unsupported collaboration systems create growing operational and compliance risk even when teams keep applying isolated fixes. Defenders should install every relevant update, review exposed servers for suspicious activity, and confirm whether anonymous access is enabled. Partial patching may leave a complete attack chain available. Fully update supported SharePoint servers and accelerate migration away from end-of-life versions.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.