Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
2 months ago

FAQ on SharePoint Zero-Day Vulnerability Exploitation (CVE-2025-53770)

On July 19, researchers at Eye Security identified active exploitation in Microsoft SharePoint Server. Originally, this exploitation was believed to have been linked to a pair of flaws (CVE-2025-49704, CVE-2025-49706) dubbed “ToolShell” that was disclosed at Pwn2Own Berlin and patched in Microsoft’s July 2025 Patch Tuesday release, Microsoft published its own blog post stating that the flaw was actually a zero-day.  

CVEDescriptionCVSSv3
CVE-2025-53770Microsoft SharePoint Server Remote Code Execution Vulnerability9.8

Microsoft confirmed that CVE-2025-53770 is a “variant” of CVE-2025-49706. As of July 20 at 2PM PST, CVE-2025-53770 remains unpatched.

Update: Since we published our community and FAQ blog post, Microsoft has created an additional CVE and added in some preliminary patches for SharePoint Subscription Edition and SharePoint Server 2019.

CVEDescriptionCVSSv3
CVE-2025-53771Microsoft SharePoint Server Spoofing Vulnerability6.3

For more information about these vulnerabilities, including the availability of patches and Tenable product coverage, please visit our blog.

No RepliesBe the first to reply