Update 7/21/25: Added links to the security updates for Microsoft SharePoint 2019. Critical zero-day vulnerabilities in Microsoft SharePoint, tracked as CVE-2025-53770 and CVE-2025-53771, have been actively exploited since at least July 18th, with no patch available and at least 85 servers already compromised worldwide. In May, Viettel Cyber Security researchers chained two Microsoft SharePoint flaws, CVE-2025-49706 and CVE-2025-49704, in a "ToolShell" attack demonstrated at Pwn2Own Berlin to achieve remote code execution. While Microsoft patched both ToolShell flaws as part of the July Patch Tuesday, it is now warning that threat actors were able to bypass the fixes with new exploits. These new vulnerabilities are tracked as CVE-2025-53770 (bypasses CVE-2025-49704) and CVE-2025-53771 (CVE-2025-49706), and are actively exploited attacks against on-premise SharePoint servers. "Microsoft is aware of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July Security Update," warns a new Microsoft blog post. "These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted." Microsoft has now released the following emergency updates for SharePoint that fix both of the zero-day flaws: "Yes, the update for CVE-2025-53770 includes more robust protections than the update for CVE-2025-49704. The update for CVE-2025-53771 includes more robust protections than the ...
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
BleepingComputer
·Published Jul 20, 2025
·Updated
Affected Software
4 affected components
Microsoft SharePoint Server=2019
Microsoft SharePoint Server=2016
Microsoft SharePoint Server Subscription Edition=23H2
Microsoft SharePoint Server (on-premises)=CVE-2025-53770/CVE-2025-53771 (zero-day pair)
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses critical zero-day vulnerabilities in Microsoft SharePoint that are being exploited for remote code execution attacks.
2
What security implications are discussed?
The vulnerabilities allow remote code execution, posing significant risks to organizations using vulnerable SharePoint versions.
3
What products or software are affected?
The affected software includes Microsoft SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition 23H2.
4
Are there any available patches for these vulnerabilities?
No, there are currently no patches available to address the exploited zero-day vulnerabilities.
5
What is the impact of not addressing these vulnerabilities?
Failing to address these vulnerabilities can lead to unauthorized access and control over affected SharePoint environments.