Patch your SharePoint before someone else gets in
A critical SharePoint server flaw could let an attacker get remote control without signing in, so if you run on-premises SharePoint you need to treat this as urgent.
This is not an email campaign. It is a vendor security warning about Microsoft SharePoint Server 2016, 2019, and Subscription Edition. If your organisation runs SharePoint on-premises, you need to treat this as an immediate server-side risk because an attacker may not need a valid account to get in and act as any user, including an administrator.
What gives it away is the way the flaw works. Researchers say the weakness can let someone reach unauthenticated remote code execution, which means your server could accept malicious commands before it has properly verified who the person is. In plain terms, your normal sign-in and permission controls may not protect you if the affected SharePoint server is exposed and unpatched.
The attacker is after control. If they can exploit this chain, they may be able to run code on the server, move through your environment, access SharePoint content, and potentially use that access to steal data or establish longer-term persistence. That turns a SharePoint weakness into a broader business systems incident very quickly.
This will matter to any NZ organisation still running affected on-premises SharePoint versions, especially where internet-facing services are in use. Security research and public disclosure make this the sort of issue other attackers will study and attempt to reproduce, which is why it can keep reappearing across different environments.
Source: The Hacker News — https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Review whether your organisation runs Microsoft SharePoint Server 2016, 2019, or Subscription Edition, particularly any on-premises or internet-facing deployments.
- Check: Confirm Microsoft's security updates have been applied and review SharePoint, Windows, and web server logs for unusual authentication, administrator actions, or code execution activity.
- Do not: Ignore vendor or agency advisories on this issue. Acting within the recommended timeframe reduces exposure significantly.
- Report: If the affected SharePoint platform is present or exploitation is suspected, contact your IT provider immediately and report suspected active exploitation to NCSC NZ at report.ncsc.govt.nz.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.

