The SharePoint flaw has now hit over 400 companies including a US nuclear administration

The Microsoft logo on a sign at the company's Redmond, Washington, headquarters.
(Image credit: VDB Photos/Shutterstock)

The SharePoint vulnerabilities that Microsoft released emergency patches for earlier this week – tracked as CVE-2025-53770 and CVE-2025-53771 – have been exploited much further than previously thought.

As reported by Bloomberg, the number of companies and organizations affected by the two exploits has grown to more than 400 in just a few days.

Article continues below

One of the highest profile agencies involved is the National Nuclear Security Administration, a U.S. agency that maintains the nations stockpile of nuclear weapons. Others include the U.S. Department of Education, Florida’s Department of Revue, and the Rhode Island General Assembly. Organizations include government agencies, education departments and technology services.


Follow Tom's Guide on Google News to get our up-to-date news, how-tos, and reviews in your feeds. Make sure to click the Follow button.

More from Tom's Guide

Network
Express VPN
NordVPN
Private Internet Access
ProtonVPN
Surfshark
Contract Length
Amber Bouman

Amber Bouman was the senior security editor at Tom's Guide where she wrote about antivirus software, home security, identity theft and more. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.