The ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint has been used by hackers thought to be connected to China in attacks on government agencies, academic institutions, telecom service providers, and financial institutions.
The security issue affects on-premise SharePoint servers and was published as an actively exploited zero-day on July 20, after various hacking groups related to China used it in massive attacks. Microsoft delivered emergency upgrades the next day.
The vulnerability is a workaround for CVE-2025-49706 and CVE-2025-49704, two vulnerabilities that researchers from Viettel Cyber Security had shown off at the Pwn2Own Berlin hacking competition in May. It may be used remotely without authentication to execute code and gain complete file system access.
Microsoft previously said that three Chinese threat groups—Storm-2603/Warlock ransomware, Budworm/Linen Typhoon, and Sheathminer/Violet Typhoon—had taken use of ToolShell read more about Sharepoint ToolShell attacks targeted orgs across four continents .
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
