ZeroHour
The Recordpublished ()ingested

Warnings issued as hackers actively exploit critical zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-53770CVE-2025-53771

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
CVE-2025-53771
Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing

CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies.

Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed.

6.5100%
  • Microsoft SharePoint Server (on-premises)
largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate)
Full article646 words · extracted from therecord.media · click to collapse

Microsoft issued an urgent alert over the weekend after threat actors were discovered exploiting a zero-day vulnerability in on-premise SharePoint servers on a global basis. 

Researchers believe the issue is likely to lead to a large number of victims including governments and enterprises, and warn that attackers are compromising cryptographic keys allowing them to maintain access to victims’ systems even after the affected servers are patched.

In emergency guidance published Saturday night, Microsoft said it was working on a patch for the remote code execution vulnerability, which is being formally tracked as CVE-2025-53770. Affected customers were urged to immediately reconfigure their systems or disconnect SharePoint until a patch is available.

A security update for SharePoint (other than the 2016 edition) was eventually released in the early hours of Monday morning, covering both CVE-2025-53770 and a less critical vulnerability registered as CVE-2025-53771.

The guidance is “uniquely urgent and drastic” according to Charles Carmakal, the chief technology officer at Google Cloud’s Mandiant consulting department.

“This isn’t an ‘apply the patch and you’re done’ situation,” Carmakal wrote on LinkedIn. “Organizations need to implement mitigations right away (and the patch when available), assume compromise, investigate whether the system was compromised prior to the patch/mitigation, and take remediation actions.”

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities catalog on Sunday with a “due date” of Monday, meaning all federal agencies are legally required to immediately fix the issue. The agency issued a similarly immediate call for federal agencies to patch the Citrix Bleed 2 bug earlier this month, at the time a record for how quickly a bug needed to be patched.

Governments compromised

Eye Security, a European cybersecurity company, said it was the first to identify the widespread exploitation of the vulnerability in the world in a blog post on Friday evening. The company scanned the internet and discovered dozens of systems that had been compromised in two waves of attacks on Friday evening and Saturday morning.

According to its blog, the company has attempted to directly inform the affected organizations and the relevant national CERTs with detailed evidence about the compromises.

Benjamin Harris, the chief executive at cybersecurity company watchTowr, which has been working with Eye Security to notify victims, warned: “All signs point to widespread, mass exploitation — with compromised government, technology, and enterprise systems observed globally.”

Michael Sikorski, the chief technology officer and head of threat intelligence for Palo Alto Networks’ Unit 42, said: “While cloud environments remain unaffected, on-prem SharePoint deployments — particularly within government, schools, healthcare including hospitals, and large enterprise companies — are at immediate risk.”

The hackers behind the compromises “are bypassing identity controls, including MFA and SSO, to gain privileged access. Once inside, they’re exfiltrating sensitive data, deploying persistent backdoors, and stealing cryptographic keys,” said Sikorski.

“The attackers have leveraged this vulnerability to get into systems and are already establishing their foothold. If you have SharePoint on-prem exposed to the internet, you should assume that you have been compromised at this point. Patching alone is insufficient to fully evict the threat,” added the CTO.

The compromise of SharePoint’s internal cryptographic keys is particularly worrying, researchers say, and means that entities that have been compromised will need to take extra steps to recycle some of the most fundamental settings used to keep themselves secure.

It “makes remediation particularly difficult,” explained Harris. “A  typical patch would not automatically rotate these stolen cryptographic secrets leaving organizations vulnerable even after they patch. In this case, Microsoft will likely need to recommend additional steps to remediate the vulnerability and any compromise post-response.”

No previous article

No new articles

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-sharepoint-zero-day-vulnerability-exploited-globally