Website Security & Threat Management
Cloudflare protects against critical SharePoint vulnerability, CVE-2025-53770

Cloudflare protects against critical SharePoint vulnerability, CVE-2025-53770

7/22/2025 · Jin-Hee Lee, Vaibhav Singhal

What this post added

This post details Cloudflare's immediate response to CVE-2025-53770, a critical SharePoint RCE vulnerability. Cloudflare's WAF Managed Rules were updated with emergency releases to mitigate the vulnerability. The post unpacks the 'ToolShell' exploit chain, explaining its three stages: authentication bypass (CVE-2025-53771), remote code execution via deserialization (CVE-2025-53770), and the long-game persistence by stealing cryptographic machine keys. It highlights the rapid development and deployment of WAF rules, tracking over 300,000 mitigation hits.

Read the original post ↗