CVE-2025-53770
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: Feb. 19, 2026
15 articles
Published: 2025-07-20
EPSS Score
Source: FIRST.org · 2026-05-24
90.21%
probability
This CVE has a 90.21% probability
of being exploited in the next 30 days.
0%
Top 99.6th percentile of all CVEs
100%
CVSS v3.1
Source: VulnerabilityLookup (CIRCL)9.8
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Temporal
Exploit Code Maturity
Functional
Remediation Level
Workaround
Report Confidence
Confirmed
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C
Description
Project ZeroDeserialization of untrusted data
Affected Products
Microsoft
Microsoft SharePoint Enterprise Server 2016
16.0.0
Microsoft
Microsoft SharePoint Server 2019
16.0.0
Microsoft
Microsoft SharePoint Server Subscription Edition
16.0.0
Attack Intelligence
Google Project Zero
Patched
July 19, 2025
Reported by
Viettel Cyber Security with Trend Zero Day Initiative
Root Cause Analysis
???
Exploits & PoC
soltanali0/CVE-2025-53770-Exploit
SharePoint WebPart Injection Exploit Tool
312
ZephrFish/CVE-2025-53770-Scanner
ToolShell scanner - CVE-2025-53770 and detection information
19
3a7/CVE-2025-53770
CVE-2025-53770 Mass Scanner
15
exfil0/CVE-2025-53770
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnera
5
4 repos — triés par ⭐
Rechercher sur GitHub ↗
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770
vendor-advisory
patch
Signal Intelligence
Confidence
95%
EPSS
90.21%
CVSS v3.1
9.8
Mentions
15
Last Seen
May 08, 2026
CNA Information
CNA Assigner
microsoft
CNA Title
Microsoft SharePoint Server Remote Code Execution Vulnerability
Analyst Note
CVE-2025-53770 is confirmed as actively exploited in the wild with a critical CVSS score of 9.8, documented exploitation by state-sponsored actors (Chinese hackers), and reported attacks against high-value targets including US nuclear weapons facilities. The vulnerability involves remote code execution through unsafe deserialization in SharePoint on-premises, with multiple credible news sources corroborating active exploitation and Microsoft acknowledging the threat.
Threat Actors 53
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Vicious Panda
apt_group
Information theft and espionage
🇨🇳 CN
Hacking Team
apt_group
🇮🇹 IT
Chamelgang
apt_group
Information theft and espionage
🇨🇳 CN
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
LAPSUS
apt_group
🇬🇧 GB
The Shadow Brokers
apt_group
🇷🇺 RU
Watchdog
apt_group
🇨🇳 CN
APT39
apt_group
Information theft and espionage
🇮🇷 IR
APT3
apt_group
Information theft and espionage
🇨🇳 CN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Volt Typhoon
apt_group
Information theft and espionage
🇨🇳 CN
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
Comment Crew
apt_group
Information theft and espionage
🇨🇳 CN
SideWinder
apt_group
🇮🇳 IN
[Unnamed group]
apt_group
🇨🇳 CN
FamousSparrow
apt_group
Information theft and espionage
🇨🇳 CN
UNC5174
apt_group
🇨🇳 CN
Earth Estries
apt_group
Information theft and espionage
🇨🇳 CN
HAFNIUM
apt_group
Information theft and espionage
🇨🇳 CN
APT31
apt_group
Information theft and espionage
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Flax Typhoon
apt_group
Information theft and espionage
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
UNC215
apt_group
Information theft and espionage
🇨🇳 CN
Water Bakunawa
apt_group
🇷🇺 RU
Bitwise Spider
apt_group
Financial gain
🇷🇺 RU
Stealth Falcon
apt_group
Information theft and espionage
🇦🇪 AE
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Radio Panda
apt_group
Information theft and espionage
🇨🇳 CN
Test Panda
apt_group
🇨🇳 CN
Circles
apt_group
Global
Pat Bear
apt_group
🇸🇾 SY
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Operation Domino
apt_group
Information theft and espionage
🇷🇺 RU
Operation Digital Eye
apt_group
Information theft and espionage
🇨🇳 CN
Unnamed Actor
apt_group
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Iron Group
apt_group
Information theft and espionage
🇨🇳 CN
Redfly
apt_group
🇨🇳 CN
Big Panda
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Cyber Alliance
apt_group
🇺🇦 UA
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
Lurk
apt_group
Financial crime
🇷🇺 RU
Storm-2460
apt_group
🇷🇺 RU
Dust Storm
apt_group
Information theft and espionage
🇨🇳 CN
Electric Panda
apt_group
🇨🇳 CN
Storm-0558
apt_group
Information theft and espionage
🇨🇳 CN
Dark Partners
apt_group
Union Panda
apt_group
🇨🇳 CN
Triage Info
Decided atFeb 19, 2026
Published DateJul 20, 2025