CVE-2025-53770General(microsoft / sharepoint_server)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft sharepoint_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-21. Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 39 mentions across 36 observed days

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 13 signals
  • General: 11 classified signals
  • Disclosure: 6 classified signals
  • Peaked 18d ago at 2 mentions (2026-03-23); latest day: 1
  • 39 total mentions across 36 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline39 mentions / 36d
01122Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-02-12: 1Mentions · 2026-02-15: 1Mentions · 2026-02-18: 1Mentions · 2026-02-24: 1Mentions · 2026-02-26: 1Mentions · 2026-03-02: 1Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-21: 1Mentions · 2026-03-23: 2Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Mentions · 2026-04-08: 1Mentions · 2026-04-11: 1Mentions · 2026-04-16: 1Mentions · 2026-04-20: 1Mentions · 2026-04-22: 1Mentions · 2026-05-01: 1Mentions · 2026-07-07: 1Mentions · 2026-07-08: 2Mentions · 2026-07-11: 1Mentions · 2026-07-15: 1Mentions · 2026-07-26: 1Mentions · 2026-08-05: 1Mentions · 2026-10-01: 1Mentions · 2026-10-02: 2Mentions · 2026-10-03: 1Mentions · 2026-10-04: 1PoC Mentioned / Linked · 2026-03-21: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-08: 2PoC Mentioned / Linked · 2026-07-26: 1Exploit Tool / Code · 2026-03-21: 1Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-07-07: 1Exploit Tool / Code · 2026-07-08: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-07-11: 1Active Exploitation · 2026-07-15: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-02-18: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 2Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 2Technical Details · 2026-07-11: 1Technical Details · 2026-08-05: 102-0402-1502-2603-0503-1403-1904-0404-1104-2207-0807-2610-0210-04
Signal classification6 categories
General
1132.4%
Active Exploitation
823.5%
Disclosure
617.6%
PoC
514.7%
Patch
38.8%
Exploit
12.9%
Referenced assets22 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-041
General1
2026-02-051
General1
2026-02-121
General1
2026-02-151
General1
2026-02-181
Patch1
2026-02-241
General1
2026-02-261
Active Exploitation1
2026-03-021
General1
2026-03-031
General1
2026-03-051
General1
2026-03-101
Active Exploitation1
2026-03-111
Disclosure1
2026-03-141
Patch1
2026-03-161
Disclosure1
2026-03-181
Disclosure1
2026-03-191
Active Exploitation1
2026-03-211
PoC1
2026-03-232
Active Exploitation1Exploit1
2026-04-041
General1
2026-04-061
General1
2026-04-081
Active Exploitation1
2026-04-111
Disclosure1
2026-04-161
General1
2026-04-201
Disclosure1
2026-04-221
Disclosure1
2026-05-011
Active Exploitation1
2026-07-071
PoC1
2026-07-082
PoC2
2026-07-111
Active Exploitation1
2026-07-151
Active Exploitation1
2026-07-261
PoC1
2026-08-051
Patch1
Full discourse20 posts
  • yousukezan@yousukezan
    PoC

    オンプレミス版Microsoft SharePoint Serverの深刻なリモートコード実行(RCE)脆弱性「CVE-2025-53770」について、概念実証(PoC)エクスプロイトコードと詳細な技術情報が公開された。 この脆弱性は、SharePointが特別に細工されたデータソースを処理する際の、信頼できないデータのデシリアライゼーションの欠陥に起因する。今回の公開により、未パッチのSharePoint環境に対する迅速な攻撃や大規模な悪用リスクが高まっている。 https://cybersecuritynews.com/poc-sharepoint-rce-vulnerability/

    Post summary

    A proof‑of‑concept exploit and detailed technical information for CVE‑2025‑53770, a SharePoint Server RCE due to a deserialization flaw, have been publicly released, increasing risk for unpatched systems but no evidence of active exploitation.

    0201982.5K
    14.9K followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet identifies the top 25 CVEs that have seen the most exploitation attempts over a 14‑day period, indicating active use by threat actors.

    070921.2K
    5.5K followersView on X
  • Dwinity@dwinity_eco
    Patch

    @barbouillech @BIT_OFIT @EJPD_DFJP_DFGP On-Prem-SharePoint hat dafür ein Muster: Bei ToolShell (CVE-2025-53770) reichte Patchen nicht, weil der gestohlene ASP.NET-MachineKey gültig blieb - Microsoft musste separat zum Rotieren auffordern. Deshalb ist "bislang keine Anzeichen für Abfluss" immer eine Momentaufnahme.

    Post summary

    The post highlights that patching alone does not mitigate CVE‑2025‑53770 because the stolen ASP.NET MachineKey stays valid, prompting Microsoft to advise rotating the key, and no exfiltration has been observed yet.

    10030152
    11.2K followersView on X
  • Sir Will@cxsnrd
    Active Exploitation

    @m1ru1 No, at least not on the machines we had access to last year. Why? CVE-2025-53770 was exploited before detection signatures existed and the SharePoint server was never imaged, so even if Defender fired, we wouldn't have that data.

    Post summary

    The post confirms that CVE‑2025‑53770 was actively exploited before detection signatures existed, but no evidence of a PoC, exploit code, patch, or technical details is given.

    110201.2K
    182 followersView on X
  • TI Mindmap HUB@ti_mindmap_hub
    Active Exploitation

    🔴 Ransomware operators are buying zero-day access. → UNC6357 exploiting SharePoint CVE-2025-53770 (CVSS 9.8) for LOCKBIT.WARLOCK deployment → Interlock exploiting a Cisco firewall zero-day BEFORE public disclosure The line between ransomware and APT tradecraft is gone.

    Post summary

    The post confirms that ransomware operators, notably UNC6357, are actively exploiting SharePoint CVE‑2025‑53770 to deploy LOCKBIT.WARLOCK, highlighting real‑world attacks without any mention of patches or workarounds.

    11010144
    9 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    General

    【アーカイブ】 【アーカイブ】 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://www.cybernote.click/2025/07/23/sharepoint%e3%81%ae%e6%9c%80%e6%96%b0%e3%82%bc%e3%83%ad%e3%83%87%e3%82%a4%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%a8%e3%81%af%ef%bc%9fcve-2025-53770-53771%e3%81%ae%e6%a6%82%e8%a6%81%e3%81%a8%e4%bc%81/?utm_source=rss&utm_medium=rss&utm_campaign=sharepoint%25e3%2581%25ae%25e6%259c%2580%25e6%2596%25b0%25e3%2582%25bc%25e3%2583%25ad%25e3%2583%2587%25e3%2582%25a4%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25a8%25e3%2581%25af%25ef%25bc%259fcve-2025-53770-53771%25e3%2581%25ae%25e6%25a6%2582%25e8%25a6%2581%25e3%2581%25a8%25e4%25bc%2581 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The post announces the existence of SharePoint zero‑day CVEs (CVE‑2025‑53770/53771) but provides no PoC, exploit, patch, or technical details.

    0003063
    30 followersView on X
  • Jλckλι@J4ck3LSyN
    PoC

    Just published a complete lab setup and PoC for CVE-2025-53770: unauthenticated remote code execution in on-premises SharePoint Server through unsafe deserialization. https://github.com/J4ck3LSyN-Gen2/CVE-2025-53770/ #CVE20253770 #InfoSec #RCE #CyberSecurity #RedTeam #VulnResearch #PoC

    Post summary

    A complete lab setup and PoC for CVE‑2025‑53770, detailing unauthenticated RCE via unsafe deserialization on SharePoint Server, have been published with a GitHub link; no active exploitation or patch information is provided.

    01010337
    175 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — WARLOCK RANSOMWARE CAMPAIGN HITS WATER AND TELECOM OPERATORS THROUGH SHAREPOINT October 1, 2026 DISCLOSED BY: Symantec / Carbon Black CONFIRMED EXPLOITED BY: Symantec / Carbon Black PRODUCT: Microsoft SharePoint Server — On-Premises CVE: Multiple SharePoint vulnerabilities are used across the campaign. Historically associated ToolShell flaws include CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. IMPACT: Symantec documented a recent Warlock campaign compromising at least four organizations, including a water utility and telecommunications provider, plus a regional government body and university. In one critical-infrastructure intrusion, attackers disabled security tooling on at least 40 hosts in roughly two hours and deployed Warlock ransomware to at least 33 systems through the domain SYSVOL share. EXPLOITATION STATUS: CONFIRMED OPERATIONAL RANSOMWARE CAMPAIGN CISA records knownRansomwareCampaignUse: Known for the core ToolShell KEV entries CVE-2025-49704, CVE-2025-49706 and CVE-2025-53770. The exact SharePoint CVE used for every recent intrusion has NOT been established. Attribution: Symantec tracks the actor as Longlegs, also associated with Storm-2603, and assesses it as China-nexus. This is NOT a formal government attribution to the Chinese state. Forensic triage: Hunt for SharePoint LAYOUTS web shells, stolen http://ASP.NET machine keys, K7RKScan/BYOVD activity, Visual Studio Code tunnels, NetExec, suspicious SYSVOL payloads and domain-wide ransomware staging. URGENT ACTION: Patch all on-premises SharePoint servers. Previously exposed systems require compromise assessment, http://ASP.NET machine-key rotation, credential review, and hunting across SYSVOL and domain controllers; patching alone does not establish that the environment is clean. SOURCE: https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json?utm_source=chatgpt.com CONFIDENCE: VERY HIGH for the campaign, victim scope and observed post-exploitation behavior based on direct Symantec/Carbon Black investigations. The China-nexus attribution is a vendor intelligence assessment, not a formal government attribution. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #ToolShell #Warlock #Storm2603 #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics

    00010129
    226 followersView on X
  • Gagan Suie@gagansuie
    Active Exploitation

    ToolShell, CVE-2025-53770. Attackers pulled http://ASP.NET machine keys, the ValidationKey and DecryptionKey, straight out of on-prem SharePoint servers.

    Post summary

    Attackers are actively exploiting CVE‑2025‑53770 to pull ASP.NET machine keys from on‑prem SharePoint servers, demonstrating real‑world impact.

    1000050
    193 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    General

    シェアポイント最新脆弱性と対策要点、企業が取るべき手順も詳解 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://www.cybernote.click/2025/07/23/sharepoint%e3%81%ae%e6%9c%80%e6%96%b0%e3%82%bc%e3%83%ad%e3%83%87%e3%82%a4%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%a8%e3%81%af%ef%bc%9fcve-2025-53770-53771%e3%81%ae%e6%a6%82%e8%a6%81%e3%81%a8%e4%bc%81/?utm_source=rss&utm_medium=rss&utm_campaign=sharepoint%25e3%2581%25ae%25e6%259c%2580%25e6%2596%25b0%25e3%2582%25bc%25e3%2583%25ad%25e3%2583%2587%25e3%2582%25a4%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25a8%25e3%2581%25af%25ef%25bc%259fcve-2025-53770-53771%25e3%2581%25ae%25e6%25a6%2582%25e8%25a6%2581%25e3%2581%25a8%25e4%25bc%2581 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces SharePoint zero‑day CVEs CVE‑2025‑53770/53771 and outlines broad mitigation steps for businesses, but it does not provide concrete technical details, PoC code, exploit tools, active attack evidence, or patch information.

    00010459
    32 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    Disclosure

    【アーカイブ】 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://www.cybernote.click/2025/07/23/sharepoint%e3%81%ae%e6%9c%80%e6%96%b0%e3%82%bc%e3%83%ad%e3%83%87%e3%82%a4%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%a8%e3%81%af%ef%bc%9fcve-2025-53770-53771%e3%81%ae%e6%a6%82%e8%a6%81%e3%81%a8%e4%bc%81/?utm_source=rss&utm_medium=rss&utm_campaign=sharepoint%25e3%2581%25ae%25e6%259c%2580%25e6%2596%25b0%25e3%2582%25bc%25e3%2583%25ad%25e3%2583%2587%25e3%2582%25a4%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25a8%25e3%2581%25af%25ef%25bc%259fcve-2025-53770-53771%25e3%2581%25ae%25e6%25a6%2582%25e8%25a6%2581%25e3%2581%25a8%25e4%25bc%2581 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces the SharePoint zero‑day CVEs‑2025‑53770/53771 and broadly discusses possible countermeasures, but provides no PoC, exploit code, active exploitation evidence, or detailed technical or patch information.

    00010125
    31 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    Disclosure

    【アーカイブ】 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://www.cybernote.click/2025/07/23/sharepoint%e3%81%ae%e6%9c%80%e6%96%b0%e3%82%bc%e3%83%ad%e3%83%87%e3%82%a4%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%a8%e3%81%af%ef%bc%9fcve-2025-53770-53771%e3%81%ae%e6%a6%82%e8%a6%81%e3%81%a8%e4%bc%81/?utm_source=rss&utm_medium=rss&utm_campaign=sharepoint%25e3%2581%25ae%25e6%259c%2580%25e6%2596%25b0%25e3%2582%25bc%25e3%2583%25ad%25e3%2583%2587%25e3%2582%25a4%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25a8%25e3%2581%25af%25ef%25bc%259fcve-2025-53770-53771%25e3%2581%25ae%25e6%25a6%2582%25e8%25a6%2581%25e3%2581%25a8%25e4%25bc%2581 #ブログ仲間と繋がりたい #Webライター

    Post summary

    This article announces the newly discovered SharePoint zero‑day vulnerabilities CVE‑2025‑53770 and CVE‑2025‑53771, summarizing their existence and offering general guidance on mitigation measures enterprises should consider.

    00010173
    31 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    Patch

    【アーカイブ】 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://www.cybernote.click/2025/07/23/sharepoint%e3%81%ae%e6%9c%80%e6%96%b0%e3%82%bc%e3%83%ad%e3%83%87%e3%82%a4%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%a8%e3%81%af%ef%bc%9fcve-2025-53770-53771%e3%81%ae%e6%a6%82%e8%a6%81%e3%81%a8%e4%bc%81/?utm_source=rss&utm_medium=rss&utm_campaign=sharepoint%25e3%2581%25ae%25e6%259c%2580%25e6%2596%25b0%25e3%2582%25bc%25e3%2583%25ad%25e3%2583%2587%25e3%2582%25a4%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25a8%25e3%2581%25af%25ef%25bc%259fcve-2025-53770-53771%25e3%2581%25ae%25e6%25a6%2582%25e8%25a6%2581%25e3%2581%25a8%25e4%25bc%2581 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The post is an informational blog that outlines the new SharePoint zero‑day vulnerabilities (CVE‑2025‑53770/53771) and explains mitigation steps or patches, without providing exploit evidence or active usage reports.

    00010228
    31 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    Disclosure

    【アーカイブ】 【アーカイブ】 SharePointの最新ゼロデイ脆弱性とは?CVE-2025-53770/53771の概要と企業が取るべき対策を解説 https://www.cybernote.click/2025/07/23/sharepoint%e3%81%ae%e6%9c%80%e6%96%b0%e3%82%bc%e3%83%ad%e3%83%87%e3%82%a4%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%a8%e3%81%af%ef%bc%9fcve-2025-53770-53771%e3%81%ae%e6%a6%82%e8%a6%81%e3%81%a8%e4%bc%81/?utm_source=rss&utm_medium=rss&utm_campaign=sharepoint%25e3%2581%25ae%25e6%259c%2580%25e6%2596%25b0%25e3%2582%25bc%25e3%2583%25ad%25e3%2583%2587%25e3%2582%25a4%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25a8%25e3%2581%25af%25ef%25bc%259fcve-2025-53770-53771%25e3%2581%25ae%25e6%25a6%2582%25e8%25a6%2581%25e3%2581%25a8%25e4%25bc%2581 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces and explains SharePoint zero‑day CVE‑2025‑53770/53771, providing an overview and recommended corporate mitigations, but it does not present PoC code, exploit tools, or evidence of active exploitation.

    00010152
    32 followersView on X
  • Cyber News Live@cybernewslive
    Active Exploitation

    A new report reveals that attackers focus on a tiny fraction of security flaws, exploiting just 1% of discovered vulnerabilities. These targeted flaws — React2Shell (CVE-2025-55182), Microsoft SharePoint (CVE-2025-53770), and SAP NetWeaver (CVE-2025-31324) — are exploited rapidly, often before patches are available. China-linked groups and ransomware gangs like Cl0p remain highly active, increasing their exploitation speed and scale. 💀 #CyberNewsLive https://hackread.com/1-security-flaws-drive-cyberattacks-2025-report/

    Post summary

    The report highlights that a small subset of newly discovered vulnerabilities—CVE-2025-55182, CVE-2025-53770, and CVE-2025-31324—are being actively exploited by threat actors before patches are released.

    0001087
    1.5K followersView on X
  • Alex@xaitax
    Patch

    For example, for a CVE there is everything in one place: severity, MS severity, CVSS breakdown, exploit status, CISA KEV, EPSS, affected products, patches, FAQs, and full revision history. https://patchapalooza.com/cve/CVE-2025-53770 It pulls fresh data from MSRC every few hours, so you'll catch revisions, score changes, and new advisories without having to check manually.

    Post summary

    The text highlights a website that aggregates patch and technical details for CVE‑2025‑53770, emphasizing the availability of fixes but providing no proof‑of‑concept or active exploitation information.

    00001155
    3.0K followersView on X
  • The Daily Tech Feed@dailytechonx

    Warlock/Longlegs is exploiting ToolShell SharePoint vulnerabilities—using CVE-2025-49704/49706 and bypasses CVE-2025-53770/53771—to breach critical infrastructure in Portuguese- and Spanish-speaking countries. From web shells to stolen machine keys, driver abuses to SYSVOL-based ransomware deployment, its tactics show patching alone isn’t enough against modern ransomware threats. #SharePoint #Ransomware #Warlock #ToolShell #Cybersecurity #CriticalInfrastructure https://thedailytechfeed.com/warlock-strikes-unpatched-sharepoint-servers-to-deploy-ransomware/

    0000072
    789 followersView on X
  • SecureChap@SecureChap

    Warlock ransomware operators chained four SharePoint CVEs for domain access on July 22. Unspecified on-prem builds were hit with CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 via ToolShell. Microsoft linked the same chain to Linen Typhoon, Violet Typhoon, and Storm-2603. Within two hours the operators dropped an AV/EDR killer to 40 hosts via BYOVD. They abused the signed K7RKScan.sys driver through CVE-2025-1055 to load a malicious kernel module and disable protections, then deployed a multi-version SharePoint web shell for persistence. NetExec handled AD enumeration and spraying while VS Code Insiders ran as a service for tunneling. Ransomware binaries were staged in the domain SYSVOL share for GPO and logon script distribution. Artifacts were deleted two days later. Warlock executed on 33 hosts by July 31 against a water utility, telecom provider, regional government, and university in Portuguese- and Spanish-speaking regions. Symantec attributes the activity to Longlegs. BYOVD via K7RKScan plus SYSVOL staging turned SharePoint access into domain-wide execution in under ten days.

    0000061
    175 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — WARLOCK RANSOMWARE ACTORS CONTINUE EXPLOITING SHAREPOINT, HITTING WATER AND TELECOM OPERATORS October 1, 2026 DISCLOSED BY: Symantec / Broadcom Threat Hunter Team CONFIRMED EXPLOITED BY: Longlegs / Storm-2603 PRODUCT: Microsoft SharePoint Server — On-Premises CVE: No single CVE is publicly confirmed for every recent intrusion. Historically associated ToolShell chain: CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 IMPACT: SharePoint exploitation → web shell → http://ASP.NET Machine Key theft → code execution → lateral movement → AV/EDR disruption → domain-scale Warlock ransomware deployment. EXPLOITATION STATUS: CONFIRMED ACTIVE EXPLOITATION CONFIRMED RANSOMWARE DEPLOYMENT CRITICAL-INFRASTRUCTURE VICTIMS CONFIRMED Forensic triage: Hunt for SharePoint LAYOUTS web shells, Machine Key theft, new privileged accounts, VS Code Tunnel services, BYOVD activity and ransomware/SYSVOL staging. URGENT ACTION: Fully patch on-prem SharePoint. Rotate http://ASP.NET Machine Keys on exposed or suspected systems and restart IIS. Investigate previously vulnerable systems before treating them as clean. SOURCE: https://www.security.com/blog-post/warlock-ransomware-critical-infrastructure EXPLOITATION UPDATE: Symantec observed at least four recent victims: a water utility, telecom operator, regional government body and university across Europe, Africa and Latin America. In one intrusion, an AV/EDR-killing tool reached 40+ hosts and Warlock ransomware was deployed to at least 33 hosts using SYSVOL replication. SUPPORTING SOURCE: https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/ CONFIDENCE: VERY HIGH — direct Symantec/Broadcom incident telemetry. HIGH — Longlegs/Storm-2603 attribution is consistent with prior Microsoft reporting. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #Warlock #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics #Storm2603

    00000116
    226 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2025-53770 Product: Microsoft / SharePoint Summary: VulnCheck reports real-world exploitation activity affecting Microsoft / SharePoint. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 18 Jul 2025 Source: https://vulncheck.com/xdb/4aa1e489b5bd #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Microsoft #SharePoint #CVE_2025_53770 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    00000105
    226 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more