July 20, 2025 — CISA added SharePoint Server CVE-2025-53770 to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
What happened
CISA added CVE-2025-53770, known as ToolShell, to the Known Exploited Vulnerabilities catalog and published guidance for affected on-premises Microsoft SharePoint environments. Later analysis described malicious files, web shells and attempts to extract cryptographic material. The issue concerned on-premises SharePoint Server, not Microsoft 365 SharePoint Online.
Why it matters
The incident demonstrates why collaboration platforms are high-value targets: they combine trusted identities, sensitive documents and connectivity to internal systems. A successful compromise may survive a simple software update if attackers have already installed persistence or stolen keys.
Security and infrastructure impact
Organizations should apply Microsoft and CISA guidance, hunt for published indicators, rotate exposed secrets where required and isolate affected systems during investigation. Recovery should include evidence review, not only patch installation.

