Critical SharePoint On-Premises Zero-Day Vulnerability (CVE-2025-30556) Under Active Attack — Urgent Steps to Protect Your Systems Now

July 25, 2025
|
Duration:
3
min READ

A critical zero-day vulnerability in Microsoft SharePoint Server on-premises deployments was recently disclosed and is currently being actively exploited in the wild. This flaw, now tracked as CVE-2025-30556, allows unauthenticated attackers to execute arbitrary code remotely, potentially leading to full server compromise and lateral movement across an organization’s network.

What Is the Risk?

According to reports from The Hacker News and KrebsOnSecurity, the vulnerability stems from insufficient input validation in SharePoint's web services and can be triggered by specially crafted SOAP requests. Microsoft has confirmed that the flaw impacts SharePoint Server 2016, 2019, and Subscription Edition, particularly in configurations that expose SharePoint to the internet or allow remote service calls internally.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities Catalog and has urged all federal agencies and private sector entities to take immediate action. (CISA Alert)

What Microsoft Has Released

Microsoft has issued out-of-band security updates and mitigation guidance for impacted SharePoint versions. These updates are designed to patch the vulnerable components and include additional telemetry improvements to detect signs of exploitation.

You can find Microsoft’s official guidance here: MSRC Advisory on CVE-2025-30556

What Customers Should Do Immediately

If you're running SharePoint Server on-premises, take the following steps right away:

  1. Apply the Patch: Download and install the security updates for your SharePoint version. Microsoft’s advisory includes specific KB articles for SharePoint 2016, 2019, and Subscription Edition.
  2. Review Internet Exposure: Evaluate whether your SharePoint services are accessible from the internet. If possible, restrict public access and require VPN or conditional access for remote use.
  3. Audit Sign-in and Service Activity: Monitor authentication logs and the SharePoint Unified Logging System (ULS) for signs of suspicious or anomalous activity. Look for unrecognized SOAP requests or new user creations.
  4. Enable Endpoint Detection and Response (EDR): Ensure EDR tools are installed on SharePoint servers and configured to alert behavioral anomalies. Microsoft Defender for Endpoint, for instance, can detect post-exploitation activity.
  5. Restrict Service Accounts: Verify that SharePoint service accounts have the least privilege necessary and do not have unnecessary local admin rights or domain-level privileges.
  6. Test in a Non-Production Environment: As with any update, validate the patch in a test environment before applying it to production systems, especially in environments with custom workflows or third-party integrations.

Identity and Access Governance Tie-In

This is another reminder that perimeter-based security is no longer sufficient. Organizations must implement strong Identity Governance, Role-Based Access Control (RBAC), Privileged Identity Management (PIM), and Privileged Access Management (PAM) for all administrative accounts, including those used by SharePoint.

Even in on-premises environments, consider extending modern identity protection tools (like Microsoft Entra) via hybrid join, Conditional Access, and Defender for Identity and strengthening access governance with PAM tools like Idira by Palo Alto Networks (formerly CyberArk).

Final Thoughts

Organizations running SharePoint on-premises should treat this vulnerability as critical and act without delay. If your team needs assistance validating patch deployment or reviewing your SharePoint architecture and access policies, MajorKey Technologies can help.

Ask yourself, do you manage your privilege access today? Who certifies them and ensures that there is zero standing privilege?

Contact MajorKey for a rapid review of your SharePoint security posture and guidance on hardening your hybrid infrastructure.

Authors

Francisco Ureña

Principal Architect
linkedin logo
Connect on LinkedIn

Recent Blogs

Blog

Notes from the Field: 5 Challenges Endemic to Copilot Rollouts

Notes from the Field: 5 Challenges Endemic to Copilot Rollouts

Copilot and agentic AI rollouts surface the permissions, labels, access paths, and adoption gaps that already exist in your environment. How do you fix them?

Blog

Understanding LDAP Signing and LDAP Channel Binding Requirements

Understanding LDAP Signing and LDAP Channel Binding Requirements

Active Directory Domain Services relies heavily on LDAP, but not every LDAP connection is automatically protected against interception, modification, or authentication-relay attacks.

Blog

Microsoft Entra ID Retires SMS & Voice Authentication: Why Passkeys Are the New Default

Microsoft Entra ID Retires SMS & Voice Authentication: Why Passkeys Are the New Default

Microsoft Entra ID is sunsetting native SMS and voice MFA to make phishing-resistant passkeys the default.

Blog

Modernizing PAM for the Identity Era: Expanding Beyond Traditional Privileged Accounts

Modernizing PAM for the Identity Era: Expanding Beyond Traditional Privileged Accounts

Learn why modern PAM strategies must extend beyond administrator accounts to include machine identities, cloud entitlements, Just-in-Time access, and Zero Standing Privilege. Dan Ross shares practical guidance for building a scalable privileged access program.

Blog

Make AI Boring

Make AI Boring

As AI becomes more deeply embedded across the enterprise, leaders must focus on the decisions, tradeoffs, and accountability required to scale responsibly.

Blog

What You Need to Know About Microsoft Entra ID’s SSPR Update and How to Mitigate its Operational Risks

Microsoft Entra ID’s SSPR Update and How to Mitigate its Operational Risks

What C-suite leaders need to know about the upcoming Microsoft Entra ID SSPR changes, its operational risks, and how to mitigate them.

Blog

Why IAM Becomes the Critical Path in Application Delivery

Why IAM Becomes the Critical Path in Application Delivery

IAM isn't why most projects start, but it's often why they stall. Learn how proactive identity governance accelerates application delivery.

Blog

TLS Certificates Are Privileged Credentials, CISOs Must Treat Them That Way

TLS Certificates Are Privileged Credentials, CISOs Must Treat Them That Way

Learn why CISOs must treat TLS certificates as machine identities to reduce outages, enforce governance, and strengthen Zero Trust.

Blog

Identity Modernization Is Dead. Long Live AI Readiness!

Identity Modernization Is Dead. Long Live AI Readiness!

AI readiness succeeds when healthcare organizations take an identity-first approach rather than a model-first one.

Blog

Evidence-Based Identity Governance for Streamlined Audits in Healthcare

Evidence-Based Identity Governance for Streamlined Audits in Healthcare

Auditors don’t just ask who has access today. Identity governance needs to be reframed as a continuous regulatory defense, not a periodic compliance exercise.

Blog

The Cost of Waiting: How Access Delays Erode Clinical Efficiency

The Cost of Waiting: How Access Delays Erode Clinical Efficiency

A modern identity strategy ensures access is there when it’s needed, protects clinical operations, and delivers measurable business value without disrupting care.

Blog

Identity Modernization: The Foundation for AI Readiness in Healthcare

Identity Modernization: The Foundation for AI Readiness in Healthcare

In a healthcare setting, AI failures can cause real harm. A strong identity foundation serves as the operational foundation for AI.

Blog

Decentralized Identity Explained: A Practical Q&A for 2026

Decentralized Identity Explained: A Practical Q&A for 2026

Explore the key concepts, benefits, challenges, and emerging trends shaping decentralized identity in 2026 and beyond.

Blog

IGA and Change Management: A Guide to Successful Engagements

IGA and Change Management: A Guide to Successful Engagements

When effective change management is integrated with IGA implementations from the start, organizations reduce resistance, increase alignment, and ensure new identity processes take root in a sustainable, scalable way.

Blog

Outcome‑Driven IAM: Why Identity Programs Win on Results, Not Tools

Outcome‑Driven IAM: Why Identity Programs Win on Results, Not Tools

Why IAM programs fail despite strong tools, and how outcome‑driven IAM delivers measurable risk reduction, audit readiness, and business value.

Blog

Breaking Down Identity Silos: Why Fragmented Systems Create Risk and Complexity

Breaking Down Identity Silos: Why Fragmented Systems Create Risk and Complexity

Learn about the challenges created by identity silos, the trade-offs between consolidation and governance, and how organizations can determine the most effective path forward.

No items found.
No items found.
No items found.