HabrJuly 28, 2026🇷🇺Translated from Russian

SOC Incident Analysis Exposes Active Exploitation of CVE-2025-53770 SharePoint ToolShell Auth Bypass and RCE

SOC analysts have published a detailed incident report on Letsdefend SOC342, covering the exploitation of CVE-2025-53770 — a critical SharePoint ToolShell authentication bypass and remote code execution vulnerability.

The alert was generated by the rule “CVE-2025-53770 SharePoint ToolShell Auth Bypass and RCE” after detecting a suspicious unauthenticated POST request to ToolPane.aspx with an abnormally large Content-Length and a spoofed referer pointing to /layouts/SignOut.aspx. The request was allowed by the security control, indicating the payload reached the server.

Initial Triage and Vulnerability Confirmation

Analysts confirmed the server was likely vulnerable because the observed behavior matched public exploitation indicators published by CISA. The source IP 107.191.58.76 was already listed in the CISA advisory and scored malicious on VirusTotal (10/92 vendors).

Network logs showed the POST request successfully reached the SharePoint server. Subsequent process telemetry revealed w3wp.exe (the IIS worker process) spawning PowerShell with the flags -nop -w hidden -e, followed by Base64-decoded commands that dumped ASP.NET machine keys.

Post-Exploitation Activity

The extracted keys would allow an attacker to forge and sign ViewState payloads, achieving unauthenticated remote code execution. The same w3wp.exe process later launched csc.exe to compile C# source code dropped in C:\Windows\Temp\payload.cs.

Attackers also created a malicious file at C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\spinstall0.aspx that used an ActiveX object (CLSID ADB880A6-D8FF-11CF-9377-00AA003B7A11) to execute or download additional payloads when a user visited the page.

  • Network IOC: 107.191.58.76 (C2 and payload hosting)
  • File hashes (SHA-256): 10e01ce96889c7b4366cfa1e7d99759e4e2b6e5dfe378087d9e836b7278abfb6 (machinekey.aspx), 92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514 (spinstall0.aspx)
  • Process chain: w3wp.exe → powershell.exe → csc.exe → cmd.exe → powershell.exe

Containment Actions

After confirming compromise, the server was isolated. Recommended remediation steps include blocking the malicious IP, deleting the dropped files, adding the observed hashes to blocklists, patching SharePoint to a safe version, and rotating all ASP.NET cryptographic keys.

Related articles

BoletimSecVulnerabilities & Exploits

Critical Stack Buffer Overflow in TP-Link TL-WR940N Enables Remote Code Execution

A high-severity vulnerability tracked as CVE-2026-12935 with a CVSS score of 8.7 affects the TP-Link TL-WR940N router on hardware version V6. The flaw resides in the RTSP connection tracking module responsible for managing audio and video streaming sessions over the network. It is caused by a stack-based buffer overflow that allows oversized data to corrupt kernel memory, potentially leading to device crashes or full remote code execution. No administrative credentials are required for exploitation, though the attack depends on an RTSP connection initiated by a device already present on the local network. Successful compromise grants attackers the ability to alter router settings, modify DNS servers, intercept traffic, redirect users to malicious sites, and pivot to other connected devices. Users are advised to verify the hardware revision on the device label and apply the region-specific firmware update released by TP-Link.

Security NEXTVulnerabilities & Exploits

N-able Releases Hotfix for Exploited N-central Authentication Bypass Flaw CVE-2026-18577

N-able has published a hotfix addressing a high-severity authentication bypass vulnerability in its N-central IT operations management platform. The flaw, tracked as CVE-2026-18577, allows attackers to bypass authentication through alternative paths or channels and potentially take over user accounts. It affects N-central 2026.1 and earlier versions and stems from an incomplete fix for the earlier CVE-2026-18556 issue. The vulnerability carries a CVSS v4.0 base score of 8.2 and is rated High severity. Exploitation has already been observed in the wild, with Indicators of Compromise including related IP addresses now publicly available. N-able released N-central 2026.3 Hotfix 1 (build 2026.3.1.7) on August 2, 2026, and urges customers to apply the update while also recommending agent updates where possible.

Security NEXTVulnerabilities & Exploits

Adobe Releases Emergency Update for Campaign Classic Fixing Multiple Critical Vulnerabilities

Adobe has issued an urgent security update for Adobe Campaign Classic to address seven critical vulnerabilities, including several with a maximum CVSSv3.1 base score of 10.0. The flaws affect on-premises deployments on Windows and Linux as well as the on-premises components of hybrid setups. Notably, the newly released fixes also impact the previous emergency update from July 29, version 7.4.3 build 9398, requiring users to apply the latest patch immediately. Among the most severe issues are a server-side request forgery vulnerability tracked as CVE-2026-48331, an input handling flaw in the template engine identified as CVE-2026-48323, and an SQL injection vulnerability labeled CVE-2026-48330. Adobe published the corresponding security advisory on August 3, 2026, urging rapid remediation despite the short interval since the prior update.

SecuritylabVulnerabilities & Exploits

Dark Patterns in Vulnerability Management: How Metrics Undermine Real Security

Vulnerability management programs often fail not due to lack of scanners but because of poorly chosen metrics that prioritize reporting over actual risk reduction. Teams focus on closing easy vulnerabilities, meeting CVSS-based deadlines, and improving dashboard numbers while attackers exploit the shortest path to critical assets. The article examines five common traps including total vulnerability counts, context-free SLAs, closure rate targets, static dashboards, and claims of no critical findings. It argues that these metrics create a false sense of security and distort team behavior according to Goodhart's Law. Instead, organizations should adopt attack path metrics, exposure management approaches such as CTEM, and measurements that track real reduction in attacker reachability. The piece highlights MaxPatrol Carbon as an example of tools that model attacker paths rather than isolated CVEs.