logo

Microsoft Rushes Emergency Patch for Actively Exploited SharePoint 'ToolShell' Bug

ID: 80203efa-ac6f-5483-b398-633cc337d3ff

STIX ID: report--80203efa-ac6f-5483-b398-633cc337d3ff

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-07-21

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Microsoft patched a critical on-premises SharePoint zero-day (CVE-2025-53770, CVSS 9.8) and a related path traversal issue (CVE-2025-53771) after wide in-the-wild exploitation of an attack chain called "ToolShell" that permits unauthenticated remote code execution and full server takeover; the wave impacted US federal and state agencies and other organizations, prompting CISA action and urgent mitigation guidance including patches, Defender deployment, and disconnecting vulnerable systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.