DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk3 min

What Is ToolShell? SharePoint Vulnerabilities and Their Risks, Explained

ToolShell is the name for 2025 exploitation activity targeting on-premises SharePoint Server. Here is what the related CVEs mean, what attackers could do, and how administrators should respond.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ToolShell is the name used for 2025 exploitation activity targeting on-premises Microsoft SharePoint Server. It is not a SharePoint product or the name of a single vulnerability: the activity involved multiple related CVEs, and successful exploitation could let attackers run code on a server and deploy web shells. Organizations running SharePoint Server should check Microsoft’s guidance for their exact version, install its applicable security update, and investigate separately if compromise is possible.

What is ToolShell?

ToolShell is the public name associated with attacks against on-premises Microsoft SharePoint Server. It describes exploitation activity or an exploit chain, rather than one formal product or one CVE. Microsoft’s guidance identifies active attacks involving CVE-2025-53770 and CVE-2025-53771; its security account also describes related activity involving earlier SharePoint vulnerabilities. Microsoft’s customer guidance and its July 22, 2025 security account provide the primary technical context.

The sequence matters because the identifiers do not all mean the same thing. Microsoft described CVE-2025-49706 as a spoofing vulnerability and CVE-2025-49704 as a remote-code-execution vulnerability in its account of earlier attacks. Later, CVE-2025-53770 and CVE-2025-53771 were described as related vulnerabilities that bypassed existing updates for earlier issues. The European Commission’s account says exploitation of a variation was detected on July 18, 2025, and that subsequent investigation identified the later vulnerabilities as zero-days that bypassed those updates. The Commission’s joint statement describes that 2025 sequence; it should not be read as saying all four CVEs are one flaw.

Does ToolShell affect SharePoint Online?

The cited advisories concern on-premises SharePoint Server. They do not establish that SharePoint Online has the same exposure, so do not assume that a cloud tenant is affected in the same way—or infer the status of a particular service from the on-premises guidance alone. Microsoft’s instructions are directed to customers running supported affected server versions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which SharePoint servers are affected?

Exposure and the correct update depend on the SharePoint Server version, edition, support status, and installed updates. Microsoft lists the supported affected versions and their applicable security updates in its customer guidance. Check that guidance against the actual deployment; a previously installed update for an earlier vulnerability should not be assumed to cover later related or bypass vulnerabilities.

What risks does ToolShell create?

The core risk is unauthorized access and code execution on an affected server. Microsoft reported web-shell use after successful exploitation. A web shell can provide an attacker with a way to issue commands or maintain access, while CISA’s related advisory context points to possible access to SharePoint content, file systems, and internal configurations. These are potential consequences, not proof that every compromised organization suffered each impact. CISA’s ToolShell notice identifies CVE-2025-53770 with that name and directs readers to its guidance.

How do I patch ToolShell?

  1. Identify the deployment. Confirm whether the organization runs on-premises SharePoint Server, then record its version, edition, support status, and installed updates.
  2. Choose the update for that exact version. Use Microsoft’s current SharePoint vulnerability guidance to find the applicable security update for a supported affected version. Do not substitute an update for a different version or rely only on a patch for an earlier related issue.
  3. Apply the update and follow the accompanying instructions. Microsoft identifies security updates intended to protect supported affected versions. Follow its current update and additional mitigation directions; installing an update does not establish that the server was never compromised.
  4. Assess compromise separately. If the server may have been exposed or shows suspicious activity, use Microsoft’s investigation guidance and the Singapore Cyber Security Agency’s remediation guide. The CSA warns that a server already patched could still be exploitable if additional mitigation measures were not applied.

What should I look for if compromise is suspected?

Microsoft reported reconnaissance involving POST requests to the ToolPane endpoint and web-shell activity after successful exploitation. Treat these as observed behaviors that can inform an investigation, not as a complete detection checklist or steps guaranteed to appear in every incident. Follow Microsoft’s current investigation instructions rather than relying on one indicator to rule an incident in or out.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about the scale of ToolShell attacks?

The cited material establishes active exploitation and dated government catalog actions, not a current total of affected organizations. CISA reported adding CVE-2025-53770 to its Known Exploited Vulnerabilities catalog on July 20, 2025, and CVE-2025-49704 and CVE-2025-49706 on July 22, 2025. Those dates document catalog actions; they are not victim counts or a 2026 estimate of how widespread compromise is.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.