Microsoft and CISA confirm exploitation of SharePoint Server vulnerability.

Microsoft and CISA confirmed active exploitation of CVE-2025-53770 ("ToolShell"), a critical unauthenticated RCE vulnerability impacting on-premises SharePoint Servers. Attackers exploit this flaw to bypass authentication, deploy malicious payloads, and achieve full remote code execution. We strongly recommend immediate patching and validation of your defenses against this threat. Our latest blog explains the exploitation steps, provides mitigation guidance, and shows how to simulate this attack using Picus Security Validation Platform. Read more: https://hubs.li/Q03x_BgC0 #Cybersecurity #SharePoint #CVE202553770 #ThreatIntelligence #PicusSecurity

  • No alternative text description for this image
John J. Gallagher

Vice President-Senior Financial Advisor

2mo

Our best offense is a strong defense. Once they are in the backfield it is to late.

Like
Reply

To view or add a comment, sign in

Explore content categories