CVE-2025-53770
KEV RANSOMWARECRITICAL 9.8EPSS 100.0%
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-07-20, used in ransomware campaigns
- Nuclei
- critical · CWE-502
- Published
- 2025-07-20
- Updated
- 2026-08-04
Proof-of-concept exploits (38)
- https://research.eye.security/sharepoint-under-siege/
- https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitati…
- https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-ratin…
- 0xray5c68616e37/cve-2025-537700★ · 2025-07-22
- 3a7/CVE-2025-5377015★ · 2025-07-29
- AdityaBhatt3010/CVE-2025-49706-SharePoint-Spoofing-Vulnerability-Under-Active-Exploitation18★ · 2025-07-20
- AdityaBhatt3010/CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE11★ · 2025-07-22
- Agampreet-Singh/CVE-2025-537700★ · 2025-08-07
- BirdsAreFlyingCameras/CVE-2025-53770_Raw-HTTP-Request-Generator0★ · 2025-07-25
- Bluefire-Redteam-Cybersecurity/bluefire-sharepoint-cve-2025-537703★ · 2025-07-21
- CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend0★ · 2025-08-13
- GreenForceNetwork/Toolshell_CVE-2025-537700★ · 2025-07-22
- GreenForceNetworks/Toolshell_CVE-2025-537700★ · 2025-07-22
- Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC4★ · 2025-07-29
- Michaael01/LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell0★ · 2025-09-24
- MuhammadWaseem29/CVE-2025-5377059★ · 2025-08-04
- Rabbitbong/OurSharePoint-CVE-2025-537702★ · 2026-02-22
- RukshanaAlikhan/CVE-2025-537700★ · 2025-07-21
- Salehswt/SharePoint-CVEs-Hunter0★ · 2025-07-22
- Udyz/CVE-2025-53770-Exploit1★ · 2025-07-25
- bharath-cyber-root/sharepoint-toolshell-cve-2025-537700★ · 2025-07-24
- bossnick98/-SOC342---CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-and-RCE0★ · 2025-07-27
- daryllundy/CVE-2025-537700★ · 2025-09-16
- exfil0/CVE-2025-537705★ · 2025-07-23
- ghostn4444/CVE-2025-537700★ · 2025-08-14
- harryhaxor/CVE-2025-53770-SharePoint-Deserialization-RCE-PoC1★ · 2025-08-02
- hazcod/CVE-2025-5377046★ · 2026-02-10
- khizar-anjum/risky-business-mcp4★ · 2025-08-17
- r3xbugbounty/CVE-2025-537700★ · 2025-07-28
- saladin0x1/CVE-2025-537704★ · 2025-09-04
- soltanali0/CVE-2025-53770-Exploit315★ · 2025-11-28
- unk9vvn/sharepoint-toolpane6★ · 2025-07-26
- 0xKr1x/CVE-2025-53770-Scanner
- J4ck3LSyN-Gen2/CVE-2025-53770
- gmh5225/ZeroPoint
- victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-Eve…
- peiqiF4ck/WebFrameworkTools-5.5-enhance
- kaizensecurity/CVE-2025-5377043★ · 2025-07-21