Log in


EMERGENCY MANAGEMENT association OF TEXAS

  • Home
  • News
  • CISA aware of active exploitation of a new remote code execution (RCE)

CISA aware of active exploitation of a new remote code execution (RCE)

22 Jul 2025 3:21 PM | Diane Weidenkopf (Administrator)

CISA is aware of active exploitation of a new remote code execution (RCE) vulnerability enabling unauthorized access to on-premise SharePoint servers. While the scope and impact continue to be assessed, the new Common Vulnerabilities and Exposures (CVE), CVE-2025-53770, is a variant of the existing vulnerability CVE-2025-49706 and poses a risk to organizations. This exploitation activity, publicly reported as “ToolShell,” provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network. 

Organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at Report@cisa.gov or (888) 282-0870. 

About EMAT

The Emergency Management Association of Texas is dedicated to the advancement of the field of emergency management both statewide and nationally. To that end, EMAT engages in an array of efforts to advance a statewide emergency management agenda and to promote the professional growth of the emergency management practitioner.

Contacts

ematinfotx@gmail.com
Address:
2502 Pace Bend Road South
Spicewood, TX 78669


Copyright © 2009-2023 Emergency Management Association of Texas ®. All Rights Reserved.
Powered by Wild Apricot Membership Software