Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Threat Intelligence

SharePoint Under Attack: Microsoft Warns of Zero-Day Exploited in the Wild – No Patch Available

Enterprises running SharePoint servers should not wait for a fix for CVE-2025-53770 and should commence threat hunting to search for compromise immediately.

SharePoint vulnerability exploited

Microsoft issued an urgent warning on Saturday to SharePoint Server customers, saying active attacks are targeting a zero-day vulnerability in the software product, which has been assigned CVE-2025-53770 with a CVSS score of 9.8.

A patch is currently not available for the flaw, dubbed “ToolShell“, which Microsoft says is a variant of CVE-2025-49706.

The Redmond, Washington-based tech giant said a security update is currently in the works and provided mitigation instructions and detection guidance. Security teams should take immediate action to implement mitigations in the meantime.

“Google Threat Intelligence Group has observed threat actors exploiting this vulnerability to install webshells and exfiltrate cryptographic secrets from victim servers,” a Google Spokesperson told SecurityWeek. “This allows for persistent, unauthenticated access and presents a significant risk to affected organizations.”

Researchers at Eye Security say they discovered “dozens of systems actively compromised,” which they say likely occurred in attacks around of July 18th around 18:00 CET and July 19th around 07:30 CET.

The Palo Alto Networks Unit42 team said on Saturday that it also has seen active exploitation of vulnerabilities for CVE-2025-49704 and CVE-2025-49706 that affect Microsoft SharePoint.

Advertisement. Scroll to continue reading.

“To protect your on-premises SharePoint Server environment, we recommend customers configure AMSI integration in SharePoint and deploy Defender AV on all SharePoint servers. This will stop unauthenticated attackers from exploiting this vulnerability,” Microsoft explained it its advisory.

“Organizations need to implement mitigations right away (and the patch when available), assume compromise, investigate whether the system was compromised prior to the patch/mitigation, and take remediation actions,” commented Charles Carmakal, CTO, Mandiant Consulting – Google Cloud.

Microsoft said it would provide updates and additional guidance as they become available.

CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog on Sunday, July 20th.

SecurityWeek will update this article and provide additional coverage as details evolved.

UPDATE, July 21: Microsoft has assigned a second CVE identifier, CVE-2025-53771, and it has started releasing patches for the ToolShell zero-days.

UPDATE, July 22: The first attack waves, which targeted high-value organizations, have been linked to China.

Helpful links and resources for CVE-2025-53770 and CVE-2025-53771:

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is founder and director of several leading cybersecurity industry conferences around the world.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Rapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.