AI Pulse by Inblix

Microsoft's SharePoint patch failed. Now it's under zero-day attack

The Register AI · Apr 28, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: Microsoft's SharePoint patch failed. Now it's under zero-day attack

Microsoft shipped a fix. It didn’t stick. On-premises SharePoint servers are now under active zero-day attack, and the timeline here is grim — the patch failure was discovered after exploitation had already begun in the wild.

This isn’t a theoretical exercise for red teams. Attackers are chaining the unpatched vulnerability with other exploits to achieve remote code execution on servers that administrators believed were secured. The specifics of the flaw haven’t been fully detailed, which is standard practice to slow copycat attacks, but the urgency in Microsoft’s revised advisory tells you everything you need to know. They’re not asking you to patch. They’re asking you to check if your patch actually worked.

The nightmare scenario for any IT manager is thinking a box is checked when it isn’t. That’s exactly what happened here. The failed patch left a door open, and someone found it. If you run SharePoint on-prem and applied the original fix, you need to verify immediately — not tomorrow, not after the weekend. The post-mortem on why the patch failed will be interesting, but right now the priority is stopping active intrusions. Microsoft hasn’t said how many servers are affected, but given SharePoint’s footprint in government and enterprise, the blast radius could be significant.

This incident is a brutal reminder that patch management hygiene isn’t about speed alone. Verification matters just as much. I’ve seen too many organizations treat the patch cycle as a compliance checkbox rather than a security function. When the vendor’s own fix fails, that assumption becomes a liability. Expect a detailed write-up from Microsoft’s security response team once the immediate fire is out, but don’t wait for it to double-check your own house.

💡 Key Takeaways

  1. A Microsoft patch for on-prem SharePoint servers failed to close the vulnerability, leaving systems exposed despite administrator action
  2. Attackers are actively exploiting the flaw in the wild, chaining it with other exploits to achieve remote code execution on compromised servers
  3. Organizations running SharePoint on-premises must immediately verify that the original patch was successfully applied rather than assuming protection

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles