Critical Sharepoint 0-Day Vulnerablity Exploited CVE-2025-53770 (ToolShell), (Sun, Jul 20th)
ID: 53caa81c-268e-5207-b172-b51bda2c0879
STIX ID: report--53caa81c-268e-5207-b172-b51bda2c0879
Feed Name: SANS ISC Diary
Threat Score
A critical SharePoint remote code execution vulnerability (CVE-2025-53770) is being actively exploited to deploy webshells; no patch is yet available. Microsoft recommends enabling AMSI for Microsoft Defender to detect post-exploit activity or disconnecting affected servers until an update is released, and research (Eye Security) plus honeypot data corroborate observed exploit attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
