Data Breaches · Web App Attack

SharePoint Patches Didn’t Clear BIT’s Breach

Patching on-prem SharePoint can close the bug and still leave an intruder trusted inside. If the attacker takes machine keys or account credentials, the server fix does not end the access problem; it just removes one path into a system that may already be compromised.

Switzerland’s federal IT office BIT says about 200 user and technical accounts were exposed after attackers used recently disclosed SharePoint flaws that Microsoft fixed in mid-July. BIT saw unusual activity on July 28, blocked internet access to the platform, and reset passwords after confirming the intrusion; it says there is no evidence of leakage beyond login credentials, and the attack may involve CVE-2026-56164 or CVE-2026-50522.

The risk now is persistence in the SharePoint trust layer. A patched server can still be dangerous if forged sign-ins or session tokens remain valid, which turns a web app flaw into an identity problem.

2 sources · Aug 7

CVE-2026-50522

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over… Microsoft patch: 5002891.

Patch available KB5002891 Download →

CISA federal remediation date Jul 25 · date passed

CVE-2026-56164

NVD KEV

Known exploited · CISA KEV

CVSS 5.3 MEDIUM: missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to… Microsoft patch: 5002891.

Patch available KB5002891 Download →

CISA federal remediation date Jul 17 · date passed

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-08-08

Every edition of this story: SharePoint Patches Didn’t Clear BIT’s Breach