Microsoft has disclosed two vulnerabilities: CVE-2025-53770 (CVSS 9.8/Critical) and CVE-2025-53771. The exploit method is referred to as a “ToolShell” attack. Find out everything you need to know in this new Risk Ledger Emerging Threats blog.
Microsoft has disclosed two vulnerabilities: CVE-2025-53770 (CVSS 9.8/Critical) and CVE-2025-53771. The exploit method is referred to as a “ToolShell” attack. These vulnerabilities affect on-premises instances of Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.
Cloud-based versions such as Sharepoint Online and Microsoft 365 are reportedly not affected.
Microsoft has released patches and additional guidance in response to this zero-day exploit.
On 19 July 2025, Microsoft issued an emergency advisory for two newly identified zero-day vulnerabilities in SharePoint Server: CVE‑2025‑53770 and CVE‑2025‑53771. These flaws bypassed the July 2025 Patch Tuesday protections for earlier vulnerabilities (CVE‑2025‑49704 and CVE‑2025‑49706). Microsoft published security updates for all vulnerable instances of on-premises SharePoint.
The severity of this threat was reinforced by recent advisories published by the UK National Cyber Security Centre (NCSC) and the US Cybersecurity and Infrastructure Security Agency (CISA).
These vulnerabilities allow attackers to gain unauthenticated access to vulnerable SharePoint servers and allow for remote code execution to access sensitive SharePoint content as well as the ability to gain access to additional systems across the network.
Organisations using the following on-premises instances of Microsoft SharePoint are affected:
SharePoint is widely used to store and manage documents, enabling teams to collaborate, edit, and process information directly or through automated workflows and other business processes.
It is important for organisations to understand whether their data is stored by any of their suppliers using these vulnerable versions of on-premises SharePoint. Data stored in on-premises SharePoint Servers may be at risk to these active exploits.
If your organisation uses the affected SharePoint versions, take the following actions as described in the Microsoft guidance:
The official Microsoft post contains up-to-date information on information and security updates affecting CVE-2025-53770 and CVE-2025-53771.
Microsoft post on Sharepoint vulnerability
Advisories from NCSC and CISA:
Additional sources of information:
Sign up to our monthly newsletter to receive exclusive research and analyses by our experts, the latest case studies from our clients as well as guides, explainers and more to turn your supply chain risk management programme into a resounding success story.