CyberzSOC

Publication detail
← Back to advisories & guidance

UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities ↗ source

July 20, 2025 CISA Alert

Summary

CISA is aware of active exploitation of a spoofing and RCE vulnerability chain involving CVE-2025-49706 and CVE-2025-49704 , enabling unauthorized access to on-premise SharePoint servers. While the scope and impact continue to be assessed, the chain, publicly reported as “ToolShell,” provides unauthenticated access to systems and authenticated access through network spoofing, respectively, and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network. Beyond the typical webshells, such as .aspx and .exe, .dll payloads have been observed during exploitation. Most recently, threat actors have also been observed encrypting files and distributing Warlock ransomware on compromised systems. While not actively exploited, Microsoft has identified the following new CVEs that pose a potential risk: CVE-2025-53771 is a patch bypass for CVE-2025-49706. If AMSI cannot be enabled, disconnect affected products from service that are public-facing on the internet until official mitigations are available.

News Coverage

DateSourceArticle
2026-08-26 Kaspersky Securelist Exploits and vulnerabilities in Q2 2026 CVE-2025-53770

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-53770 9.8 Critical Microsoft SharePoint Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execu…
CVE-2025-49704 8.8 High Microsoft SharePoint Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerabili…
CVE-2025-49706 6.5 Medium Microsoft SharePoint Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Success…
CVE-2025-53771 6.5 Medium Microsoft Microsoft SharePoint Enterprise Server 2016 Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.