MBSD-SOC reported active exploitation attempts against on-premises Microsoft SharePoint Server flaws CVE-2025-53770 and CVE-2025-53771, vulnerabilities disclosed on 2025-07-19 that can enable authentication bypass and arbitrary code execution. The activity was first observed by the SOC on 2025-07-22 and affected SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Observed requests included a Referer header pointing to /_layouts/SignOut.aspx, indicating an apparent attempt to bypass authentication before further compromise.
The report said attackers are also chaining CVE-2025-49704 and CVE-2025-49706 with the newer SharePoint flaws in an attack path referred to as ToolShell, allowing unauthenticated compromise and control of vulnerable SharePoint servers. MBSD-SOC said many attack sources were traced to the United States, followed by Japan, France, Germany, and Hong Kong, and urged organizations to apply Microsoft security updates immediately to reduce exposure to internet-facing SharePoint systems.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft released security updates for SharePoint Server 2016 on 22 July 2025, following updates for SharePoint Server Subscription Edition and SharePoint Server 2019, to address the actively exploited CVE-2025-53770 vulnerability.
MBSD-SOC reported first seeing attack traffic targeting CVE-2025-53770 and CVE-2025-53771, including requests to SharePoint ToolPane paths and use of the Referer header '/_layouts/SignOut.aspx' in an apparent authentication-bypass attempt.
MBSD-SOC states that the Microsoft SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 were publicly disclosed, affecting on-premises SharePoint Server deployments and enabling authentication bypass and possible remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
mbsd.jp
Open sourcencsc.nl
Open sourcemsrc.microsoft.com
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.