PGH Networks

Active SharePoint Exploit: What Pittsburgh SMBs Should Do Now

August 13, 2026· PGH Networks Team· 4 min readCloud & Microsoft 365
Active SharePoint Exploit: What Pittsburgh SMBs Should Do Now

What happened

Attackers have started using a proof-of-concept exploit for a critical Microsoft SharePoint vulnerability that was published by researchers at Rapid7, according to reporting from BleepingComputer. The window between public PoC and real-world attacks was, as usual, measured in hours rather than days.

Because the article does not enumerate every affected build or CVE detail in the excerpt we reviewed, the first task for any SharePoint operator is to open the source, confirm the specific CVE identifier and patch level called out by Microsoft's advisory, and match that against your own environment before assuming you are covered. Do not take our word (or anyone's word) for whether your servers are in scope, verify against Microsoft's Security Update Guide directly.

man walking on stairs

Why this matters for Pittsburgh SMBs

SharePoint is one of those platforms that quietly runs a huge amount of the professional-services economy in Western PA. If you are a 40-person CPA firm in the Strip, a law firm in the USX Tower, a specialty clinic in Monroeville, or a Tier-2 defense manufacturer out toward Latrobe, there is a strong chance SharePoint (either on-prem Server or SharePoint Online tied to hybrid infrastructure) is holding client files, engagement workpapers, matter documents, PHI, or CUI right now.

That matters for three concrete reasons:

  • On-prem SharePoint Server is the higher-risk footprint. SharePoint Online in Microsoft 365 is patched by Microsoft. On-prem Server 2016/2019/Subscription Edition deployments (still common in law firms, manufacturers, and hybrid Azure setups) are your responsibility to patch, and they are the systems typically hit in campaigns like this.
  • Regulators will ask. For firms under HIPAA, SOC 2, the FTC Safeguards Rule, or working toward CMMC Level 2, an unpatched, internet-reachable SharePoint server hosting regulated data is exactly the kind of finding that turns an incident into a reportable event. DFARS 7012 72-hour reporting clocks do not care that the PoC was only a few days old.
  • Ransomware crews weaponize these fast. SharePoint exploits are attractive because they typically yield authenticated code execution on a server that already has broad access to file shares, service accounts, and often a path to domain identity. That is a ransomware operator's ideal beachhead.

What to do about it this week

Assuming today is mid-August 2026, here is a realistic checklist your internal IT lead or MSP should be able to knock out in the next five business days:

  1. Inventory every SharePoint instance you own. On-prem Server, hybrid, and any third-party-hosted SharePoint farms. Include dev/test boxes, they get forgotten and they get exploited. If you cannot produce this list in an hour, that itself is the finding.
  2. Verify patch status against Microsoft's advisory. Pull the CVE from the BleepingComputer article, cross-reference Microsoft's Security Update Guide, and confirm each server is at or above the fixed build. Do not rely on "auto-updates are on" — verify the installed CU/security update explicitly.
  3. Take internet-facing SharePoint off the public internet if you can. If external access is not a business requirement, put it behind the VPN or a reverse proxy with MFA today. If it must be public, at minimum restrict by geo and known IP ranges via WAF.
  4. Hunt for indicators of prior compromise. Patching a box that is already backdoored just locks the attacker in with you. Review IIS logs, w3wp.exe child processes, unexpected .aspx files in LAYOUTS/TEMPLATE directories, and new local admins or service-account logons over the last 14 days. This is where a proper EDR or MDR tool earns its keep.
  5. Rotate machine keys and service-account credentials on any SharePoint server that was internet-exposed before patching. Assume secrets on the box are burned until proven otherwise.
  6. Confirm backups are recoverable, not just running. Test-restore a SharePoint content database to an isolated environment. Immutable or offline copies only — anything an attacker with domain admin can delete is not a backup.
  7. Brief the humans. Tell partners, department heads, and compliance officers what happened, what you checked, and what you are doing. For regulated firms, document the review — that memo is a compliance artifact if anyone asks later.

If you are on SharePoint Online only (pure Microsoft 365, no on-prem Server), items 2-5 largely do not apply to you for this specific bug, but items 1, 6, and 7 still do. And it is a good prompt to revisit conditional access, external sharing settings, and Microsoft Purview DLP policies while the topic is fresh.

three people collaborating in open office

How we help

PGH Networks runs patch management, 24x7 monitoring, and threat hunting for SMBs across Pittsburgh's professional services, healthcare, legal, and defense-contractor communities. We handle the SharePoint inventory-and-verify drill above as part of standard managed IT, and for regulated clients our vCIO team ties each incident like this back to your HIPAA, SOC 2, or CMMC control evidence so audits are not a scramble later. If you are not sure whether your SharePoint footprint is patched, exposed, or already touched, that is exactly the question we can answer this week.

Talk to us

Call 724.888.7007 or reach out through the contact form and we will get a SharePoint exposure check on your calendar.

Share

Related reading

Call usBook a meeting