On 18 July 2025, exploitation began against two SharePoint Server vulnerabilities collectively named ToolShell. CVE-2025-53770 carries a CVSS score of 9.8 and allows unauthenticated remote code execution with no user interaction. Within days, more than 400 organizations across government, telecommunications and software had been compromised, by three separate China-linked groups.
Among them was the National Nuclear Security Administration, the agency responsible for the United States nuclear weapons stockpile.
One detail in the advisories deserves more attention than it got: the flaw affected on-premises SharePoint servers, and not the same product running inside a Microsoft 365 tenant.
What actually happened
| Element | Detail |
|---|---|
| CVEs | CVE-2025-53770, CVE-2025-53771 |
| Authentication required | None |
| User interaction required | None |
| Affected | On-premises SharePoint Server 2016, 2019, Subscription Edition |
| Not affected | SharePoint within a Microsoft 365 tenant |
| Scale | 400+ organizations, days |
Unauthenticated remote code execution with no user interaction is the shortest possible path from stranger to code. There is no credential to steal, no user to phish, no session to hijack. There is a server that answers, and a request that takes it over.
The gap: the same software, two very different exposures
The on-premises versus cloud split is the most instructive part of this incident, and it is not really a statement about which product is better engineered.
An on-premises SharePoint server that staff need to reach from outside the office gets published. Once published it answers everyone, and "everyone" includes an automated campaign enumerating SharePoint instances across the internet. The cloud tenant sits behind an access layer that does not work that way.
A population of servers that will answer anybody is not a set of installations. It is a target list, and it can be generated in an afternoon.
Four hundred organizations in days is not four hundred targeted operations. It is one campaign against everything that would reply.
The NNSA's own outcome supports the reading. Its impact was reported as limited, attributed substantially to how much of the department had moved to the Microsoft 365 cloud. The agency was not saved by a superior detection capability. It was saved by having fewer servers that answered strangers.
What would have had to be true
The patch is the correct fix and it arrived, as patches do, after exploitation had already started. CISA added the flaw to its Known Exploited Vulnerabilities catalog and directed emergency updates.
Between the start of exploitation and the completion of patching across a large estate, the only variable an organization controls is who its servers will answer.
An on-premises SharePoint server reachable only from the networks its own attested users are connecting from is not in the scan results. The vulnerability is still present. The exploit still works. It has nowhere to be delivered from.
That is not equivalent to being patched, and it should not be described as such. It is the difference between an urgent patching window and an incident response.
Where Veribound would have fitted
Veribound is an intelligence layer. It does not patch SharePoint, does not proxy traffic, and does not replace the access controls in front of it.
Agents attest that devices are still the ones the organization trusted. The scoring engine turns those attestations into per-device decisions, A trusted origin is the network that device is connecting from, in practice its public address, while the device behind it is still trusted. Those origins are written into the address groups the organization's own edge policy already references.
Applied here:
- The enumeration campaign does not find the server, because it does not answer an unrecognized network.
- Unauthenticated RCE stops being reachable by strangers, which is the only population that had it.
- The patch is still required and the patching window stops being the window in which the organization is defenseless.
What it would not have done: it does not fix the vulnerability, and it offers nothing against an attacker already inside a trusted network. It also does not make on-premises a better choice than the cloud tenant. What it does is give an on-premises server the property the cloud tenant had by default in this incident, which is not answering the internet at large.
Organizations run on-premises SharePoint for real reasons: data residency, integration, cost, or contracts that predate the cloud. Those reasons should not carry a hidden term reading "and therefore reachable by every scanner on the internet."
Source: US Nuclear Agency Hacked in Microsoft SharePoint Frenzy, Dark Reading, 23 July 2025.