Microsoft released security updates for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016, including corresponding language pack updates, to address actively exploited SharePoint vulnerabilities. The flaws include CVE-2025-53770, a critical unauthenticated remote code execution issue caused by unsafe deserialization of untrusted data, and CVE-2025-53771, a spoofing flaw tied to improper path validation for sensitive files; reporting linked their exploitation to the ToolShell campaign targeting government, academic, and energy organizations worldwide. Microsoft published update packages including KB5002768 for Subscription Edition, KB5002754 and KB5002753 for SharePoint 2019 core and language pack, and KB5002760 and KB5002759 for SharePoint 2016 and its language pack.
U.S. CISA also added a critical SharePoint deserialization flaw, CVE-2026-50522, to its Known Exploited Vulnerabilities catalog after public proof-of-concept code and reports of active attacks. According to the advisory, attackers have stolen SharePoint machine keys to preserve access even after patching, prompting guidance to patch immediately, rotate potentially exposed credentials and cryptographic material, enable protections such as AMSI and Microsoft Defender AV, and investigate systems for indicators of compromise including webshells, suspicious files, malicious URLs, paths, and IP addresses.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-50522, a critical Microsoft SharePoint deserialization flaw, to its Known Exploited Vulnerabilities catalog. The reporting says the flaw was being actively exploited after a public proof-of-concept release and that attackers were reportedly stealing SharePoint machine keys for persistence after patching.
CSIRT.SK reported that the exploited SharePoint flaws were used in a campaign dubbed ToolShell against dozens of government, academic, and energy institutions worldwide. The notice also published indicators of compromise including webshell, file, URL, path, and IP indicators tied to the attacks.
Microsoft released security updates for SharePoint Subscription Edition, SharePoint 2019, and SharePoint 2016 to fix CVE-2025-53770 and CVE-2025-53771, which were described as actively exploited vulnerabilities. The updates include packages for SharePoint Server 2016, SharePoint Server 2016 Language Pack, SharePoint Server 2019 Core, SharePoint Server 2019 Language Pack, and SharePoint Server Subscription Edition.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcegovcert.bg
Open sourcecsirt.sk
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.