The news: A major security flaw in Microsoft SharePoint is actively being exploited by hackers around the world. The full impact is still unfolding, but 100 large companies, thousands of SMBs, and at least two US federal agencies have been breached.
- The vulnerability affects on-premises SharePoint editions; cloud-based Microsoft 365 and SharePoint Online users are unaffected, per The Register.
- The flaw (CVE-2025-53770) scores 9.8 out of 10 in severity and lets attackers break into on-premises SharePoint servers without needing login credentials.
“Security updates have been released for supported products, and organizations are urged to apply them immediately, rotate machine keys, and closely monitor server activity,” Microsoft stated in a blog post.
Zooming out: This incident comes two months after Microsoft cut 3% of its workforce—between 6,000 and 7,000 employees—including roles in security, support, and QA.
The company is shifting resources toward AI and cloud growth, raising concerns that security is being sidelined in favor of speed.
IP, client data, and campaigns exposed: Security updates pushed out Monday won’t help companies that have been compromised in the past 72 hours. These attacks have no obvious signs like pop-ups or ransom notes to notify users they’ve been hit.
For agencies with on-premises SharePoint servers, this exposes client data, campaign data, ad platforms, CMS, and analytics dashboards.
Our take: Microsoft’s restructuring toward AI and cloud has left cracks in its legacy infrastructure, now exploited at scale. For agencies and marketers, the risk is real: Compromised systems mean vulnerable campaigns and lost client IP, data, and brand reputation. For Microsoft, continued breaches could push customers to abandon SharePoint altogether.
This content is part of EMARKETER’s subscription Briefings, where we pair daily updates with data and analysis from forecasts and research reports. Our Briefings prepare you to start your day informed, to provide critical insights in an important meeting, and to understand the context of what’s happening in your industry. Non-clients can click here to get a demo of our full platform and coverage.