Attackers are already using a hole in on-premises SharePoint (Microsoft's document software) - in real attacks, not in theory. CISA added it to the list of actively exploited vulnerabilities and set a patching deadline. Microsoft had rated it as unlikely to be attacked.
- A code-execution vulnerability in on-premises SharePoint is being actively exploited.
- CISA added it to the catalog of actively exploited holes and set a federal patching deadline.
- Affected: SharePoint 2016/2019/Subscription (on-premises); cloud SharePoint Online is not.
A vulnerability in on-premises SharePoint Server allows code execution by an attacker with valid credentials (username and password) and ordinary site-member rights. It's not theory - it's already being used in real attacks. That's why CISA added it to the catalog of actively exploited holes and set a patching deadline for federal agencies.
I'll allow myself an opinion here: what matters is the gap between the vendor's assessment and what attackers actually do. 'Unlikely to be exploited' doesn't mean safe. It just means no one has tried it publicly yet. If CISA sets a deadline, someone has already tried it successfully.
Running on-premises SharePoint? Stop reading. Act. The patch is available, the clock is running. Cloud installs are off the hook, but the forgotten on-premises server is exactly the classic open door.