Critical SharePoint zero-day exploited in global attacks — no patch yet for 2016

July 21, 2025

A critical zero-day in Microsoft SharePoint Server is being actively exploited in global cyberattacks, affecting at least 54 organizations across multiple sectors. Tracked as CVE-2025-53770, the flaw has a severity score of 9.8 and currently has patches for later versions but no patch is available for the 2016 version. Attackers can execute code remotely without authentication.

The campaign began around July 18 and is targeting on-premises SharePoint installations. Victims include government agencies, banks, and multinational corporations across the U.S., Europe, and Asia. Microsoft confirmed the attacks over the weekend and says it’s working on an emergency update.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalogue on Sunday. Federal agencies have been ordered to apply mitigations by Monday. Dutch cybersecurity firm Eye Security, which first identified the exploit, says the threat actors are still launching mass attacks.

Dubbed “ToolShell” by researchers, the bug is linked to Microsoft’s earlier CVE-2025-49706, a spoofing issue patched in July. ToolShell exploits deserialization of untrusted data in SharePoint, allowing attackers to install web shells, steal cryptographic keys, and forge tokens for persistent access. Microsoft advises enabling Antimalware Scan Interface (AMSI) and Defender Antivirus, or disconnecting affected servers from the internet. SharePoint Online is not impacted.

Top Stories

Related Articles

April 29, 2026 Google has signed an agreement with the U.S. Department of Defense allowing its artificial intelligence models to more...

April 29, 2026 OpenAI is reportedly developing a smartphone centred on an AI “agent” interface designed to replace traditional app-based more...

April 28, 2026 China’s top economic planner has ordered Meta to unwind its proposed $2 billion acquisition of AI startup more...

April 27, 2026 Google plans to invest up to $40 billion in Anthropic, starting with an initial $10 billion at more...

Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com
Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn