Attackers breached the Swiss federal government’s on-premises SharePoint servers and compromised approximately 200 user and technical accounts before the intrusion was detected. The Federal Office for Information Technology and Communications known as FOITT, confirmed the breach after identifying anomalies roughly a week after the initial access. The investigation remains open.
The two vulnerabilities exploited are tracked as CVE-2026-56164 and CVE-2026-50522. CVSS scores have not been published for either at time of writing. The attack targeted on-premises SharePoint infrastructure, not a cloud-hosted environment which matters because Microsoft’s automatic update mechanisms do not apply to self-hosted deployments. Organisations running SharePoint on their own servers are responsible for applying patches themselves and the Swiss case is a direct illustration of what happens when that process falls behind.
What FOITT Has Confirmed
FOITT’s public statement is narrow but specific, there is “no indication that any data beyond the compromised login credentials was accessed.” That is a meaningful distinction. Credential theft without data exfiltration suggests the attacker’s primary objective was access rather than immediate extraction though it does not rule out lateral movement that pre-dates the anomalies FOITT identified. The investigation will need to establish how far the attackers moved inside the network before detection.
On-Premises SharePoint Is a Different Risk Category
The distinction between SharePoint Online and on-premises SharePoint Server is worth stating plainly because it determines who carries the patching burden. SharePoint Online, hosted in Microsoft 365, receives security updates from Microsoft automatically. SharePoint Server, hosted on an organisation’s own infrastructure, does not. Every CVE that Microsoft patches in SharePoint Server requires the operator to download and apply that fix manually.
Government agencies across Europe have historically run on-premises SharePoint deployments for data sovereignty reasons. That is a legitimate policy choice. It is also one that requires a disciplined patch management programme to remain defensible and the FOITT breach suggests that programme had a gap.
The honest assessment here is that two CVEs whose CVSS scores have not been published make it difficult to evaluate how quickly organisations should have been expected to act. The absence of severity scores from NIST’s National Vulnerability Database at time of writing is a problem for anyone trying to prioritise remediation. Treat both as high severity until NIST publishes otherwise.
No Named Nordic Company in the Source Data
The source material contains no confirmed breach of a named Nordic organisation linked to these CVEs. The generic claim in the briefing notes that the incident “highlights the importance of cybersecurity for all organisations, including those in Sweden” is not worth printing. If a Swedish or Finnish government agency running on-premises SharePoint Server discloses an incident tied to CVE-2026-56164 or CVE-2026-50522, that will be a story. Until then, the Swiss breach stands on its own terms.
Apply Both Patches Before Auditing Access Logs
If your organisation runs SharePoint Server on-premises, apply the patches for CVE-2026-56164 and CVE-2026-50522 immediately. Check Microsoft’s Security Update Guide for the relevant cumulative update for your SharePoint Server version.
After patching, audit authentication logs for anomalous access patterns over the past 30 days, not just the past week. The FOITT case illustrates a detection lag, anomalies were identified approximately a week after initial access which means earlier activity may not have triggered alerts. Look for service accounts authenticating at unusual hours, accounts accessing SharePoint content outside their normal scope and any authentication events tied to accounts that should not have active sessions.
Disable any SharePoint accounts that are no longer in active use. Technical accounts with broad permissions and no active owner are exactly the kind of credential that makes lateral movement easy once an attacker has initial access.
References
- Swiss Government SharePoint Breach Compromised 200 Accounts
- Swiss IT Agency Hacked, 200 Accounts Compromised, SharePoint Vulns Suspected
- Swiss Federal IT Agency FOITT Compromised About 200 Accounts Due to SharePoint Flaws
- Swiss Federal IT Office Hit by Cyberattack
- Microsoft Security Update Guide
This post is also available in: