SharePoint Vulnerabilities Compromise ~200 Accounts at Swiss Federal IT Agency
What Happened — On July 28, the Swiss Federal Office for Information Technology and Communications (FOITT) detected anomalous activity on its on‑premises SharePoint servers. Attackers leveraged unpatched SharePoint flaws—including CVE‑2026‑50522 (CVSS 9.8)—to compromise roughly 200 user and technical accounts. FOITT reset the affected passwords, blocked external SharePoint access, and began rebuilding the servers.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of why SOC 2 access‑control (CC6.1 System Operations, CC6.2 Change Management) evidence must be continuously collected and auditable.
- Rapid patch deployment and documented credential‑reset procedures are required to demonstrate due‑diligence and a defensible audit trail.
- Continuous control‑mapping lets organizations prove that critical software updates are applied across all environments, a key control gap highlighted by this breach.
Who Is Affected – Federal government IT services (public sector), with downstream impact on any organization that runs on‑premises SharePoint without timely patching.
Recommended Actions
- Verify that every SharePoint instance is patched to the latest Microsoft security update; retain patch‑compliance logs as audit evidence.
- Review access‑control policies: enforce MFA, enforce least‑privilege, and ensure password‑reset actions are fully logged.
- Map the incident to SOC 2 CC6.1/CC6.2 controls, collect supporting evidence, and update your incident‑response playbook.
Technical Notes – The exploited flaw (CVE‑2026‑50522) allows remote code execution with low complexity; attackers were observed stealing machine keys for persistent access. No confirmed data exfiltration has been reported. Source: SecurityAffairs