logo

ToolShell: Details of CVEs affecting SharePoint servers

ID: bf2f4203-36f9-57af-aca6-12e4767536aa

STIX ID: report--bf2f4203-36f9-57af-aca6-12e4767536aa

Feed Name: Cisco Talos

Threat Score
85/100

Date Published: 2025-07-21

Date Updated: 2026-04-27

Author: Cisco Talos

...
...

Cisco Talos describes active exploitation in the wild of unauthenticated SharePoint Server path traversal/RCE vulnerabilities (CVE-2025-53770 and CVE-2025-53771) affecting on‑premises SharePoint Server (2016, 2019, Subscription Edition). Microsoft and CISA have released patches and guidance; Talos and other vendors published detections (Snort SIDs 65092/65183, ClamAV SharpyShell signature, Splunk analytics) and recommend applying updates, rotating ASP.NET machine keys, and enabling AMSI to mitigate post-compromise activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.