Microsoft Corp. deployed an emergency security update on Sunday, July 20, targeting a SharePoint Server vulnerability that attackers are actively leveraging to infiltrate organizations. Reports indicate that malicious actors have already exploited the flaw to compromise systems at U.S. federal and state agencies, academic institutions, and power sector organizations.
The vulnerability, tracked as CVE-2025-53770, affects on-premises SharePoint Server deployments. Microsoft's advisory notes that the company is aware of ongoing exploitation attempts against these customers, and that the flaw represents a variant of an earlier weakness that the July 8, 2025 security update failed to fully resolve. The Cybersecurity & Infrastructure Security Agency (CISA) confirmed this assessment, linking CVE-2025-53770 to CVE-2025-49706, which Microsoft had patched earlier in the month. Cloud-based offerings including SharePoint Online and Microsoft 365 remain unaffected.
The Washington Post reported that authorities in the United States, Canada, and Australia are coordinating an investigation into the SharePoint server breaches. At minimum, two U.S. federal agencies have had their systems compromised through exploitation of the SharePoint vulnerability.
According to CISA, threat actors are installing a backdoor tool called "ToolShell" on compromised servers to maintain persistence. This backdoor grants unauthenticated remote access, allowing attackers to browse SharePoint content, examine file systems and internal settings, and run arbitrary code across the network.
Researchers at Eye Security detected widespread exploitation beginning on July 18, 2025. The team identified dozens of infected servers containing ToolShell and determined that attackers were targeting SharePoint server ASP.NET machine keys.
These keys can be used to facilitate further attacks, even at a later date. It is critical that affected servers rotate SharePoint server ASP.NET machine keys and restart IIS on all SharePoint servers. Patching alone is not enough. We strongly advise defenders not to wait for a vendor fix before taking action. This threat is already operational and spreading rapidly.
Eye Security
Microsoft has released patches for SharePoint Server Subscription Edition and SharePoint Server 2019. However, updates for supported versions of SharePoint 2019 and SharePoint 2016 remain in development.
CISA recommends that vulnerable organizations take several defensive measures while awaiting official patches. These include enabling the anti-malware scan interface (AMSI) within SharePoint, deploying Microsoft Defender AV across all SharePoint servers, and isolating affected systems from internet-facing networks.
Security researchers at Rapid7 have noted that CVE-2025-53770 relates to CVE-2025-49704, which Microsoft patched earlier this month. That earlier vulnerability was part of an exploit chain demonstrated at the Pwn2Own hacking competition in May 2025, which also leveraged CVE-2025-49706—a flaw that Microsoft attempted to address during this month's Patch Tuesday but ultimately failed to fully remediate.
Microsoft has also released a patch for CVE-2025-53771, an additional SharePoint weakness. The company reports no evidence of active exploitation of this vulnerability and characterizes the patch as providing enhanced protections beyond what the CVE-2025-49706 update delivers.
Source: Krebs on Security