Many businesses store their most important documents - quotes, contracts, drawings, customer files - in Microsoft SharePoint. Convenient, because everyone in the organisation works in it daily and it’s easy to share with colleagues, suppliers and customers. It now turns out there’s a serious security flaw in SharePoint that’s currently being actively exploited by attackers. Reason enough to pause on this, even if you have no IT background yourself.
What exactly is going on?
Security researchers have found a flaw in SharePoint that allows an attacker, without logging in, to gain access to a SharePoint server. Once inside, that person can reach all the documents stored there, and in some cases even move further into the network. The particularly concerning part is that this flaw is already being actively used in attacks, while many organisations haven’t yet installed the corresponding patch (fix).
Cloud or your own server: the distinction that matters right now
Here’s the key thing to know: the flaw sits specifically in SharePoint Server, the version businesses run themselves on their own server (on-premise). If you use SharePoint Online, part of Microsoft 365, Microsoft manages that environment itself and installs the necessary updates automatically. For most smaller businesses that run everything through Microsoft 365, this particular flaw is therefore not a direct threat.
Not sure whether you’re running your own SharePoint server, perhaps because it was once set up to share drawings with a production team or documents with logistics partners? Ask your IT administrator or IT partner. It’s a thirty-second question with potentially major consequences.
Why this is relevant to your business
In wholesale, manufacturing, and transport & logistics especially, SharePoint is often used to share documents across the supply chain: quotes with customers, contracts with suppliers, drawings with subcontractors, schedules with transport partners. If an attacker gains access through this flaw, all that data is essentially exposed. That doesn’t just affect your business, but potentially also the customers and partners whose data you manage. It can damage your operations as well as the trust others place in you.
What should you have done now?
As a director, you don’t need to fix this yourself, but you are the one responsible for making sure it happens. Make sure the following points are carried out, either by your own IT department or your IT partner:
1. Determine whether you’re vulnerable. Check whether anywhere in the organisation a self-managed SharePoint Server is running (not SharePoint Online within Microsoft 365).
2. Install the available patch immediately. Microsoft has released emergency updates to close the flaw. The sooner this is installed, the smaller the risk that you still fall victim.
3. Check for signs of misuse. Because the flaw is already being actively exploited, patching alone isn’t enough. Have it checked whether unauthorised access already took place before patching, for example through log files.
4. Renew security keys. If misuse has already occurred, an attacker with stolen keys can sometimes still get in even after patching. Have relevant keys and passwords renewed where there’s reason to do so.
5. Decide together with your IT partner whether moving to the cloud makes sense. This isn’t mandatory, but organisations that move to SharePoint Online leave this kind of maintenance to Microsoft going forward, which structurally reduces this type of risk.
A concrete plan for today
You don’t need to remember this article, but you do need to ask whoever is responsible for IT at your company: “Are we running our own SharePoint server anywhere, and if so, has the patch been installed and has it been checked for misuse?” If the answer is unclear, that in itself is a signal that it’s worth having this looked into properly.
A few questions we’re often asked
We work with Microsoft 365, are we at risk too?
If all your documents are in SharePoint Online, part of Microsoft 365, you’re not directly vulnerable to this specific flaw, because Microsoft manages and patches that environment itself. It’s still a good moment to confirm this with your IT partner, since some businesses unknowingly still run an old, self-managed SharePoint environment alongside Microsoft 365.
How do I find out if we’ve already been affected?
That’s not something you can see yourself; it requires investigation of log files and system settings by someone with technical knowledge. Ask your IT partner to check this explicitly, even if everything looks normal to you.
We’ve already installed the patch, are we done then?
The patch prevents new attacks through this flaw, but if an attacker already got in before patching, they may sometimes still have access through previously stolen data. Always have it checked for signs of earlier misuse too, and renew keys and passwords where needed.
Is it wise to switch to SharePoint Online now?
That depends on your situation, but it’s certainly worth considering. With SharePoint Online, Microsoft takes over the maintenance and patching of your environment, so acute flaws like this are less likely to affect your business. Discuss with your IT partner what that would mean for your specific setup.
Want to know whether your business is affected by this SharePoint flaw, or simply want your document management checked over? We’re happy to think it through with you.