logo

Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated July 31)

ID: 3a294ca0-ba80-50f2-9ec5-a0b758b39832

STIX ID: report--3a294ca0-ba80-50f2-9ec5-a0b758b39832

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2025-07-31

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 reports widespread, in-the-wild exploitation of multiple critical on-premises Microsoft SharePoint vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) enabling unauthenticated RCE used to install web shells, exfiltrate cryptographic MachineKeys and deliver payloads including 4L4MD4R ransomware; the brief provides IoCs, telemetry (activity timeline and targeting patterns), attribution to CL-CRI-1040/overlap with Storm-2603, and recommended mitigations and hunting queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.