Customer guidance for SharePoint vulnerability CVE-2025-53770 Summary Microsoft is aware of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July Security Update These vulnerabilities apply to on-premises SharePoint Servers only SharePoint Online in Microsoft 365 is not impacted Microsoft has released security updates that fully protect customers using SharePoint Subscription
Microsoft Releases Guidance on Exploitation of SharePoint . . . and poses a risk to organizations This exploitation activity, publicly reported as “ToolShell,” provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network
Microsoft alerts businesses and governments to attacks on . . . Microsoft has issued an alert about “active attacks” on server software used by government agencies and businesses to share documents within organizations and recommended security updates that