// Alert

Microsoft 365 threat report

Microsoft SharePoint Server on-premises versions are vulnerable to the ToolShell exploit chain (CVE-2025-53770), which combines authentication bypass and unsafe deserialization to enable unauthenticated remote code execution. Linen Typhoon (APT27), Violet Typhoon (APT31), and Storm-2603 exploited the flaw in the wild beginning July 18, 2025, within days of Microsoft's advisory. The attack requires two HTTP requests with forged headers and malicious payloads. CVSS score is 9.8. SharePoint Online in Microsoft 365 cloud is not affected; patches are available for on-premises Server versions 2016, 2019, and Subscription Edition.

// Get alerts for Microsoft 365