logo

SharePoint zero-day: What we know

ID: 18d7a4be-6521-5dd2-a86d-87a6bd7ef804

STIX ID: report--18d7a4be-6521-5dd2-a86d-87a6bd7ef804

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2025-07-22

Date Updated: 2026-04-29

Author: Carolynn van Arsdale

...
...

Microsoft warned that attackers are actively exploiting multiple SharePoint vulnerabilities — including zero‑day CVE‑2025‑53770 (CVSS 9.8) — via a ToolShell chain to deploy backdoors and steal system keys on on‑premises SharePoint (Subscription Edition, 2019, 2016). A PoC disclosed at Pwn2Own was rapidly weaponized and, since mid‑July, scans and reports indicate numerous compromises across U.S. federal/state agencies, critical infrastructure, higher education and telecommunications; Microsoft and CISA have released patches and mitigation steps (rotate machine keys, enable AMSI, use AV/EDR).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.