Warlock Ransomware Is Exploiting SharePoint: Check Your Patch Status Now
A China-linked ransomware group called Warlock is actively exploiting a chain of unpatched Microsoft SharePoint vulnerabilities to break into corporate networks and deploy ransomware. If your business runs SharePoint Server on its own hardware, you need to verify your patch status today.
According to BleepingComputer's 2 October 2026 report, confirmed victims already include a water utility, a telecom provider, and a regional government body. The group, also tracked as "Longlegs" by Symantec, chains four SharePoint vulnerabilities to gain web shell access, then moves laterally before deploying ransomware.
The four flaws being exploited: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Microsoft patched all four in 2025. If your on-premises SharePoint hasn't received those updates, those vulnerabilities are still open.
If your business is on SharePoint Online via Microsoft 365, you're protected: Microsoft applies patches automatically. This advisory is for organisations running SharePoint Server themselves, on hardware or a private server.
We've seen this pattern with Australian clients in aged care, transport, and professional services. A single missed patch window can leave an on-premises SharePoint exposed for months. Warlock has been active since at least June 2025 and is escalating its target list.
What to do right now
- Check your SharePoint patch level. Open SharePoint Central Administration, go to Upgrade and Migration, then Review database status. Compare your build number against Microsoft's SharePoint update history and confirm CVE-2025-49704, 49706, 53770, and 53771 are covered.
- Restrict external access. If your SharePoint is internet-facing (even partially), lock access to known IP ranges or put it behind a VPN until patches are confirmed applied.
- Review recent web logs. Look for unusual POST requests to SharePoint's /_layouts/ paths or unexpected file uploads. These are early indicators of web shell activity.
- Test your backups. Run a restore drill. Ransomware-targeted environments need an offline or air-gapped backup that wasn't connected during the potential attack window.
SharePoint Updates, Microsoft Learn
Frequently Asked Questions
Does the Warlock ransomware threat affect Microsoft 365 or SharePoint Online users?
No. If your business uses SharePoint Online through a Microsoft 365 subscription, Microsoft applies security patches automatically. You are protected. The risk is specific to organisations running SharePoint Server on their own hardware or a private server.
Which SharePoint vulnerabilities is Warlock exploiting?
Warlock chains four SharePoint flaws: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Microsoft patched all four in 2025. If your on-premises SharePoint hasn't received those updates, those vulnerabilities remain open to exploitation.
How do I check whether my SharePoint is patched?
Go to SharePoint Central Administration, then Upgrade and Migration, then Review database status. Compare the build number against Microsoft's official SharePoint update history. Your IT provider can also run this check for you.
What does Warlock do once inside a network?
After exploiting SharePoint, Warlock deploys web shells for persistent access, then uses BYOVD (Bring Your Own Vulnerable Driver) techniques to disable endpoint detection tools before triggering ransomware encryption. This makes early detection difficult with traditional antivirus alone.
Not sure if your SharePoint is patched?
Our team can run a rapid patch status check for your SharePoint environment before ransomware exploits the gap.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
