CISA Confirms Active Exploitation of SharePoint ToolShell Vulnerability

July 20, 2025 — CISA added SharePoint Server CVE-2025-53770 to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

What happened

CISA added CVE-2025-53770, known as ToolShell, to the Known Exploited Vulnerabilities catalog and published guidance for affected on-premises Microsoft SharePoint environments. Later analysis described malicious files, web shells and attempts to extract cryptographic material. The issue concerned on-premises SharePoint Server, not Microsoft 365 SharePoint Online.

Why it matters

The incident demonstrates why collaboration platforms are high-value targets: they combine trusted identities, sensitive documents and connectivity to internal systems. A successful compromise may survive a simple software update if attackers have already installed persistence or stolen keys.

Security and infrastructure impact

Organizations should apply Microsoft and CISA guidance, hunt for published indicators, rotate exposed secrets where required and isolate affected systems during investigation. Recovery should include evidence review, not only patch installation.

Sources

← Back to Technology News