CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks

CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks

The U.S. CISA has added two Microsoft SharePoint vulnerabilities, CVE-2025-49704 and CVE-2025-49706, to its KEV list following active exploitation by Chinese hacking groups. Organizations are urged to remediate these flaws by July 23, 2025, to prevent unauthorized access and potential breaches. #CISA #SharePointVulnerabilities

Keypoints

  • CISA has identified two critical SharePoint flaws actively exploited by threat actors.
  • Chinese hacking groups Linen Typhoon and Violet Typhoon have targeting on-premise SharePoint servers since July 2025.
  • The vulnerabilities include remote code execution, spoofing, and authentication bypass issues.
  • Microsoft’s advisories confirm exploitation of CVE-2025-53770, which also bypasses security mitigations like AMSI.
  • Security experts emphasize timely patching over reliance on mitigations such as AMSI to prevent breaches.

Read More: https://thehackernews.com/2025/07/cisa-orders-urgent-patching-after.html