On-premises Microsoft SharePoint servers are under threat from twin remote code execution (RCE) vulnerabilities.
Revealed last week by Microsoft, the critical zero-day vulnerabilities, tracked as CVE-2025-53770 and CVE-2025-53771, have seen active exploitation since at least July 18. Security firm Eye Security told Bleeping Computer that 85 servers have been compromised, affecting 54 organizations.
Michael Sikorski, CTO and head of threat Intelligence for Unit 42 at Palo Alto Networks, told SDxCentral that “on-prem SharePoint deployments – particularly within government, schools, and healthcare, including hospitals and large enterprise companies – are at immediate risk”.
The CTO explained that the “high-severity, high-urgency threat” allows attackers to bypass identity controls, including MFA and SSO, to gain privileged access.
“Once inside, they’re exfiltrating sensitive data, deploying persistent backdoors, and stealing cryptographic keys,” Sikorski explained.
“The attackers have leveraged this vulnerability to get into systems and are already establishing their foothold. If you have SharePoint on-prem exposed to the internet, you should assume that you have been compromised at this point.”
While patches weren’t available with the original Microsoft warnings regarding the cybersecurity threat, the company has since released emergency patches for Microsoft SharePoint Subscription Edition and SharePoint 2019.
Both flaws stem from spoofing bugs tracked as CVE-2025-49706 and CVE-2025-49704, together dubbed as ToolShell, which were discovered through a hackathon in May of this year.
Microsoft patched both bugs as part of July’s Patch Tuesday update from the company, but attackers were able to circumvent these patches a week later.
On recommended next steps for network security, Unit 42’s Sikorski stressed, “patching alone is insufficient to fully evict the threat.”
“We are urging organizations who are running on-prem SharePoint to take action immediately and apply all relevant patches now and as they become available, rotate all cryptographic material, and engage professional incident response.
“An immediate, band-aid fix would be to unplug your Microsoft SharePoint from the internet until a patch is available. A false sense of security could result in prolonged exposure and widespread compromise.”
Sikorski highlighted SharePoint’s deep integration with Microsoft’s platform, comprising the backbone of many companies' enterprise work tools today through Office, Teams, OneDrive, and Outlook.
As the flaws affect on-premises servers, the cloud-based SharePoint Online service from Microsoft is not affected.
The SharePoint discovery follows similar RCE threats to Cisco software and Fortinet products, the underlying issue of which was a buffer overflow in C-based code, in contrast to the logic-based exploit of the Microsoft hack.
Comments