
Over the last weekend, numerous cybersecurity agencies revealed new cybersecurity attacks targeting on-premises SharePoint Server customers by exploiting unpatched vulnerabilities. The CVE-2025-53770, also referred to as ToolShell, enables attackers to gain control of SharePoint servers without authentication.
Microsoft is aware of these active attacks and announced that these issues are partially addressed by the July Security Update. It is important to note that these vulnerabilities affect only on-premises SharePoint Servers. Microsoft specifically highlighted that SharePoint Online in Microsoft 365 is not impacted.
Customers can download the July Security Update for Microsoft SharePoint Server Subscription Edition and Microsoft SharePoint Server 2019 using the following links:
- Microsoft SharePoint Server Subscription Edition - KB5002768
- Microsoft SharePoint Server 2019 - KB5002754
While Microsoft is working to release a hotfix to address this security vulnerability completely, customers can follow the following steps to mitigate the issue:
- Use supported versions of on-premises SharePoint Server.
- Apply the latest security updates, including the July 2025 Security Update.
- Ensure the Antimalware Scan Interface (AMSI) is turned on and configured correctly, with an appropriate antivirus solution such as Microsoft Defender Antivirus.
- Deploy Microsoft Defender for Endpoint protection or an equivalent endpoint threat solution.
- Rotate SharePoint Server ASP.NET machine keys.
Microsoft also noted that Microsoft Defender Antivirus can already detect if a server is affected by this vulnerability. Customers can find these threats under the following detection names:
- Exploit:Script/SuspSignoutReq.A
- Trojan:Win32/HijackSharePointServer.A
"Our team scanned 8000+ SharePoint servers worldwide. We discovered dozens of systems actively compromised, probably on July 18th around 18:00 UTC and July 19th around 07:30 UTC," wrote the cybersecurity research firm, Eye.
Given the active exploitation of this vulnerability, it is crucial for all on-premises SharePoint administrators to apply the latest security updates and implement the recommended mitigation steps immediately.
.png)
![The Perfect Router Does Not Exi [video]](https://www.youtube.com/img/desktop/supported_browsers/firefox.png)

