A critical patch bypass vulnerability that circumvents fixes for CVE-2025-49704 from the actively exploited ToolShell campaign. Deserialization of untrusted data in on-premises SharePoint Server enables unauthenticated remote code execution over the network. Microsoft confirms active exploitation in the wild. Mitigation: Enable AMSI integration with Microsoft Defender across SharePoint farms, or disconnect public-facing SharePoint servers from the internet. Microsoft 365 SharePoint Online is unaffected.