logo

Cato CTRL™ Threat Brief: “ToolShell” Exploit Targeting Microsoft SharePoint Vulnerabilities 

ID: 1e797385-1c34-5daa-ac42-fd47179a3088

STIX ID: report--1e797385-1c34-5daa-ac42-fd47179a3088

Feed Name: Cato Networks

Threat Score
90/100

Date Published: 2025-07-24

Date Updated: 2026-07-23

Author: Guy Waizel

...
...

On July 22, 2025 Microsoft disclosed a chain of critical SharePoint Server vulnerabilities being actively exploited via a multi-stage exploit dubbed "ToolShell," which achieves unauthenticated RCE, deploys web shells, exfiltrates cryptographic keys, and enables persistent signed payload execution; Microsoft observed exploitation by two named Chinese nation-state actors and issued emergency updates while Cato describes SASE/XDR protections to detect and block exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.