Technology expertise and solutions for Canadian businesses 1 (888) 976-3111 Sign In

Is Your SharePoint Server Exposed? Five Checks to Make Now

When a critical SharePoint alert arrives, the hardest part is often knowing whether your business is actually exposed. A closed patch ticket can create reassurance without answering the questions that matter: which servers are affected, whether every update was verified, and whether anyone checked for suspicious activity.

Three critical vulnerabilities disclosed in July affect on-premises SharePoint Server. They can allow an unauthorized attacker to elevate privileges, bypass a security feature, or run code over a network. Exploitation has been reported against one of the July flaws and earlier SharePoint vulnerabilities, so this is an exposure-and-verification problem—not a routine patch reminder.

First, confirm whether this applies to you

“We use SharePoint” is not enough information. A business may use a cloud service, an on-premises SharePoint Server farm, or both. The July alert applies to Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.

Ask the person or provider responsible for your environment to identify every on-premises SharePoint Server instance, including systems that are not used every day. Record the product edition, installed build, server owner, internet exposure, last update, and monitoring contact. If no one can answer, treat that uncertainty as work to resolve today.

Check the installed build, not the patch ticket

A closed ticket does not prove every server received the update. Compare the installed build on each SharePoint server with the fixed build for its edition.

SharePoint Server editionFixed build to reach or exceed
Enterprise Server 201616.0.5561.1001
Server 201916.0.10417.20175
Subscription Edition16.0.19725.20434

The immediate job is to apply the current security updates and verify the resulting build on every affected server. Change records should show which systems were updated, who confirmed the build, whether a restart or service interruption occurred, and what validation followed.

Do not confuse patching with incident clearance

Patching closes known vulnerable code. It does not prove that a server was clean before the update. Review affected systems for unusual requests, web shells, malicious processes, unauthorized access attempts, unexpected privilege changes, suspicious access to IIS machine keys, and relevant Defender or antimalware detections.

That review needs an owner and an escalation path. If suspicious activity appears, preserve useful evidence and move into the organization’s incident process. Avoid making ad hoc changes that could erase the information responders need.

For teams improving this operating discipline, managed security monitoring can help define log sources, alert handling, escalation, and investigation responsibilities before an event. A broader security strategy roadmap can place urgent remediation beside longer-term risk and lifecycle work.

Use this five-check decision helper

This two-minute check turns the alert into a next action. It is a prioritization aid, not a vulnerability scan or a declaration that an environment is secure. Answers are processed only in this page and are not stored or transmitted.

SharePoint Server response check

Choose the best-known answer. “Not sure” is a useful result because it identifies an ownership or evidence gap.

1. Do you operate SharePoint Server on your own infrastructure?
2. Which on-premises edition is installed?
3. Has someone verified every server is at or above the fixed build?
4. Can any SharePoint Server be reached directly from the internet?
5. Has the team reviewed the servers for suspicious activity?

This check runs locally in your browser. It does not send or save your answers.

Turn the result into owned work

If the result calls for immediate review, write down the affected systems, technical owner, business contact, next action, and time of the next update. Urgency is easier to manage when responsibility and communication are visible.

If the environment is patched and reviewed, the lifecycle decision still matters. SharePoint Server 2016 and 2019 reached the end of support on July 14, 2026. A final security update does not make an unsupported product a stable long-term destination. Plan the supported-version path, dependencies, testing, rollback, ownership, and business timing.

An IT risk register can keep any accepted delay visible, with an owner and review date. For ongoing maintenance, vendor coordination, and lifecycle planning, managed IT support can put the work into a dependable service rhythm.

The useful outcome is proof

The strongest response is not “the update should be installed.” It is a short evidence package: the server inventory, installed builds, exposure decision, threat-review result, incident escalation if needed, and supported-version plan.

Start by asking for those six items. If the answers are incomplete, you have found the next work—not a reason to assume the risk is handled.

General information: This article does not replace advice based on your organization’s systems, obligations, and risk.

What can we help you solve?

We’ll listen, clarify what matters, and help you choose a practical next step.