Switzerland's Federal IT Office Hit Through Unpatched SharePoint Servers
Switzerland's Federal Office for Information Technology and Telecommunication (BIT) confirmed that attackers exploited vulnerabilities in its Microsoft SharePoint servers — the document management and collaboration platform used across the Swiss federal government — compromising roughly 200 employee accounts, according to Bleeping Computer.
Security analysts spotted the unusual activity on 28 July. BIT confirmed the breach three days later, then immediately blocked external access to SharePoint, patched the relevant flaws, and reset all affected passwords.
The likely culprits are two vulnerabilities Microsoft fixed in its July 2026 Patch Tuesday release. The first, CVE-2026-56164, is a privilege escalation flaw (a bug that lets an attacker gain more access than they should have). The second, CVE-2026-50522, is a remote code execution vulnerability — meaning an attacker who exploits it can run their own commands on the server. BIT has not confirmed which flaw was used.
The good news: no evidence of data theft beyond the login credentials, and BIT says sensitive or confidential data was not permitted on that SharePoint environment. Servers are being rebuilt from scratch as a precaution.
The uncomfortable truth: the patches were already available. BIT just had not applied them yet when the attackers arrived.
What you should do: If your organisation uses Microsoft SharePoint, confirm July's Patch Tuesday updates have been applied. If external access to SharePoint is not required, restrict it at the network level. If it is required, block it temporarily until patching is confirmed.
Sources

