logo

CVE-2025-53770 & CVE-2025-53771: Critical On-Prem SharePoint Vulnerabilities

ID: b87d6b61-676e-5575-b42a-4cedcd4ee6c9

STIX ID: report--b87d6b61-676e-5575-b42a-4cedcd4ee6c9

Feed Name: Cybereason Blog

Threat Score
92/100

Date Published: 2025-07-22

Date Updated: 2026-04-27

Author: Cybereason Consulting Team

...
...

**Executive summary:** Two critical zero-day vulnerabilities in on‑premises Microsoft SharePoint (CVE-2025-53770 CVSS 9.8 and CVE-2025-53771) are being actively exploited in the wild; Cybereason and other vendors observed webshell deployments, encoded PowerShell execution and exploitation patterns tied to China‑linked groups and follow‑on eCrime actors, and recommend assuming compromise, immediate patching, isolating affected servers, rotating ASP.NET machine keys, searching for POSTs to /_layouts/15/ToolPane.aspx?DisplayMode=Edit and suspicious .aspx files, and conducting historical incident response lookbacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.