CISA Warns of New Exploit Targeting Microsoft SharePoint

CISA Warns of New Exploit Targeting Microsoft SharePoint

Hackers Exploit Microsoft SharePoint Servers; CISA Issues Urgent Warning

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert warning organizations of an active exploitation campaign targeting on-premises Microsoft SharePoint servers. According to CISA’s July 20 report, the attack—known publicly as “ToolShell”—takes advantage of server vulnerabilities to grant attackers full access to internal systems.

“This exploitation activity… provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content,” CISA said in its July 20 report. The agency is currently assessing the full impact of the breach.

Microsoft acknowledged the threat on July 19, confirming that only on-premises servers are affected—SharePoint Online on Microsoft 365 is not at risk. Updates have been released for SharePoint Subscription Edition and SharePoint 2019, while patches for SharePoint 2016 are pending.

Both CISA and Microsoft urge system administrators to install the latest security updates, enable Antimalware Scan Interface (AMSI), and deploy Microsoft Defender for Endpoint. In cases where AMSI cannot be activated, CISA recommends temporarily disconnecting affected systems from the internet.

The exploit, listed under CVE-2025-49706, has been added to CISA’s Known Exploited Vulnerabilities catalog. Organizations are encouraged to review their logging practices, reduce administrative privileges, and follow Microsoft’s advanced mitigation strategies.

With over 200,000 organizations relying on SharePoint globally, the attack underscores growing cybersecurity challenges. CISA further warned of increasing threats to cloud infrastructure, calling for enhanced public-private cooperation to defend digital assets.

Related Posts
Brewers eye NL Central lead against Cubs
The Milwaukee Brewers will have an opportunity to climb into first place in the National
CPS enrollment falls as CTU membership grows
Chicago Public Schools has lost nearly one-fifth of its student population over the past decade,
Indian student killed in crash near Chicago
An Indian student was killed, and several others were injured, following a late-night two-vehicle crash
Trump says China to order 200 Boeing jets
Boeing could secure its largest Chinese aircraft deal in years after U.S. President Donald Trump
FIFA unveils World Cup final halftime show
The 2026 FIFA World Cup final will introduce a major entertainment addition inspired by the
Chicago Fire stadium to be named McDonald’s Park
The Chicago Fire have secured a major naming rights agreement with McDonald’s for the club’s
Eovaldi seeks another strong outing vs D-backs
Nathan Eovaldi will try to continue his recent turnaround Monday night when the Texas Rangers
Tesla recalls Cybertrucks over wheel defect
Tesla has announced two separate recalls, including a limited number of Cybertrucks affected by a
Onco advances cancer therapy development phase
Onco-Innovations Limited announced a new milestone in the development of its cancer treatment platform, confirming
Trout homer lifts Angels past White Sox
Mike Trout continued to climb the all-time home run list, powering the Los Angeles Angels