logo

ToolShell Zero-day: Microsoft Rushes Emergency Patch for Actively Exploited SharePoint Vulnerabilities

ID: d2a36569-bdd0-55de-b9df-d7e6b1e22ef8

STIX ID: report--d2a36569-bdd0-55de-b9df-d7e6b1e22ef8

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2025-07-21

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

On July 19, 2025, Qualys published guidance on two zero-day vulnerabilities in Microsoft SharePoint Server—CVE-2025-53770 (critical RCE, CVSS 9.8, actively exploited as “ToolShell”) and CVE-2025-53771 (path-traversal spoofing, CVSS 6.3)—affecting multiple on-premises SharePoint versions; the advisory details impact, evidence of active exploitation (Microsoft, CISA, NHS), Qualys detection QIDs, and urgent mitigation/patching steps via Qualys VMDR/CSAM and TruRisk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.