CVE-2025-49704
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
14 articles
EPSS Score
Source: FIRST.org · 2026-05-24
59.58%
probability
This CVE has a 59.58% probability
of being exploited in the next 30 days.
0%
Top 98.3th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
ToolShell Zero-day: Microsoft Rushes Emergency Patch for Actively Exploited SharePoint Vulnerabilities
Qualys
Jul 21, 2025
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and More
TheHackerNews
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access
TheHackerNews
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company Servers
TheHackerNews
CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks
TheHackerNews
Microsoft and Adobe Patch Tuesday, July 2025 Security Update Review
Qualys
Jul 08, 2025
Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks
TheHackerNews
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks
BleepingComputer
Jul 21, 2025
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
BleepingComputer
Jul 20, 2025
Microsoft July 2025 Patch Tuesday fixes one zero-day, 137 flaws
BleepingComputer
Jul 08, 2025
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems
TheHackerNews
Microsoft links Sharepoint ToolShell attacks to Chinese hackers
BleepingComputer
Jul 22, 2025
Signal Intelligence
Confidence
92%
EPSS
59.58%
Mentions
14
Last Seen
Jul 22, 2025
CNA Information
Analyst Note
Article [2] explicitly names this CVE as a SharePoint zero-day exploited in RCE attacks with no patch available at time of exploitation report. Article [1] confirms emergency patches were released for SharePoint RCE flaws exploited in active attacks. The CVE publication date (2025-07-08) aligns with Microsoft's July 2025 Patch Tuesday, indicating exploitation preceded or coincided with patch availability.
Threat Actors 61
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Vicious Panda
apt_group
Information theft and espionage
🇨🇳 CN
Evil Corp
apt_group
Financial crime
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
LAPSUS
apt_group
🇬🇧 GB
The Shadow Brokers
apt_group
🇷🇺 RU
Dropping Elephant
apt_group
Information theft and espionage
🇮🇳 IN
APT3
apt_group
Information theft and espionage
🇨🇳 CN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Just Evil
apt_group
🇷🇺 RU
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
Lucky Cat
apt_group
Information theft and espionage
🇨🇳 CN
HomeLand Justice
apt_group
Sabotage and destruction
🇮🇷 IR
Predatory Sparrow
apt_group
Sabotage and destruction
🇮🇱 IL
Pirate Panda
apt_group
Information theft and espionage
🇨🇳 CN
[Unnamed group]
apt_group
🇨🇳 CN
FamousSparrow
apt_group
Information theft and espionage
🇨🇳 CN
Silent Lynx
apt_group
Information theft and espionage
🇰🇿 KZ
Earth Estries
apt_group
Information theft and espionage
🇨🇳 CN
APT31
apt_group
Information theft and espionage
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Rocke
apt_group
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
UNC215
apt_group
Information theft and espionage
🇨🇳 CN
Bitwise Spider
apt_group
Financial gain
🇷🇺 RU
UNC2891
apt_group
Financial gain
🇨🇳 CN
Stealth Falcon
apt_group
Information theft and espionage
🇦🇪 AE
Silent Crow
apt_group
🇺🇦 UA
COOKIE SPIDER
apt_group
🇷🇺 RU
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Radio Panda
apt_group
Information theft and espionage
🇨🇳 CN
Test Panda
apt_group
🇨🇳 CN
Circles
apt_group
Global
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Operation Domino
apt_group
Information theft and espionage
🇷🇺 RU
Operation Digital Eye
apt_group
Information theft and espionage
🇨🇳 CN
Unnamed Actor
apt_group
🇨🇳 CN
TRAVELING SPIDER
apt_group
Financial gain
🇷🇺 RU
The Big Bang
apt_group
Information theft and espionage
🇵🇸 PS
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
SINGING SPIDER
apt_group
🇺🇸 US
Mana Team
apt_group
🇨🇳 CN
Impersonating Panda
apt_group
🇨🇳 CN
Liminal Panda
apt_group
🇨🇳 CN
Redfly
apt_group
🇨🇳 CN
Nazar
apt_group
Information theft and espionage
🇮🇷 IR
Big Panda
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Cyber Alliance
apt_group
🇺🇦 UA
Predator Panda
apt_group
🇨🇳 CN
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
LightBasin
apt_group
Information theft and espionage
🇨🇳 CN
Dust Storm
apt_group
Information theft and espionage
🇨🇳 CN
Electric Panda
apt_group
🇨🇳 CN
Storm-0558
apt_group
Information theft and espionage
🇨🇳 CN
Dark Partners
apt_group
Unit 29155
apt_group
Sabotage and destruction
🇷🇺 RU
Union Panda
apt_group
🇨🇳 CN
Triage Info
Decided atMar 05, 2026