logo

Critical Sharepoint 0-Day Vulnerablity Exploited CVE-2025-53770 (ToolShell), (Sun, Jul 20th)

ID: 53caa81c-268e-5207-b172-b51bda2c0879

STIX ID: report--53caa81c-268e-5207-b172-b51bda2c0879

Feed Name: SANS ISC Diary

Threat Score
85/100

Date Published: 2025-07-21

Date Updated: 2026-04-19

...
...

A critical SharePoint remote code execution vulnerability (CVE-2025-53770) is being actively exploited to deploy webshells; no patch is yet available. Microsoft recommends enabling AMSI for Microsoft Defender to detect post-exploit activity or disconnecting affected servers until an update is released, and research (Eye Security) plus honeypot data corroborate observed exploit attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.