AI Pulse by Inblix

Microsoft's SharePoint patch fails, leaving servers open to zero-day attacks

The Register AI · Apr 28, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: Microsoft's SharePoint patch fails, leaving servers open to zero-day attacks

Microsoft’s latest security updates were supposed to lock things down. Instead, they kicked open a door that’s now being actively exploited. A patch intended to fix an on-prem SharePoint vulnerability didn’t actually fix it — and attackers noticed before most admins did. The result is a zero-day situation where unpatched servers are getting hit in the wild.

The flaw sits in SharePoint Server, the kind of legacy on-prem software that quietly runs inside thousands of organizations. When Microsoft shipped its fix, the assumption was that applying it meant you were safe. That assumption was wrong. Security researchers are now tracking active exploitation attempts against the very vulnerability the patch was supposed to close. This isn’t a theoretical risk — it’s a live campaign.

What makes this particularly ugly is the trust model. Admins who diligently applied the update believed they’d checked the box. They hadn’t. The gap between “patched” and “protected” is where these attacks live, and Microsoft hasn’t yet clarified how long the ineffective fix was in place or when a working patch will land. For organizations running SharePoint on-prem, the guidance right now is a mess of partial mitigations and crossed fingers.

This lands in a week that also saw China upgrading smartphone surveillance tools and Ring quietly walking back some anti-snooping features. But the SharePoint failure stings differently. It’s not a sophisticated supply chain attack or a novel zero-day discovered by some elite research team. It’s a broken fix from one of the world’s most critical software vendors — the kind of unforced error that keeps security teams up at night because there’s no defense against the tools that are supposed to defend you.

💡 Key Takeaways

  1. A Microsoft SharePoint patch failed to remediate the vulnerability it was designed to fix, leaving patched servers still exploitable.
  2. Attackers are actively exploiting this gap in the wild, turning a routine update cycle into a zero-day incident.
  3. Organizations trusting the patch status alone have a false sense of security — manual mitigations are necessary until Microsoft ships a working fix.
  4. The incident underscores the fragility of patch-based trust models in enterprise software, especially for on-prem systems.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles