Microsoft Rushes Emergency Patch for Actively Exploited SharePoint 'ToolShell' Bug
ID: 80203efa-ac6f-5483-b398-633cc337d3ff
STIX ID: report--80203efa-ac6f-5483-b398-633cc337d3ff
Feed Name: Dark Reading
Date Published: 2025-07-21
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Microsoft patched a critical on-premises SharePoint zero-day (CVE-2025-53770, CVSS 9.8) and a related path traversal issue (CVE-2025-53771) after wide in-the-wild exploitation of an attack chain called "ToolShell" that permits unauthenticated remote code execution and full server takeover; the wave impacted US federal and state agencies and other organizations, prompting CISA action and urgent mitigation guidance including patches, Defender deployment, and disconnecting vulnerable systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
