CyberzSOC

Publication detail
← Back to advisories & guidance

2025-027: Critical Vulnerabilities in Microsoft SharePoint ↗ source

July 24, 2025 CERT-EU Advisory

Summary

These vulnerabilities apply to on-premises SharePoint Servers only. These critical flaws are actively being exploited in the wild since at least 18th of July 2025 [4]. It is recommended isolating vulnerable system from the Internet, but also from internal systems, and running a compromise assessment before updating. The vulnerability CVE-2025-53770, with a CVSS score of 9.8, is due to the deserialisation of untrusted data. This flaw allows an unauthorised attacker to execute code over a network [2].

News Coverage

DateSourceArticle
2026-08-26 Kaspersky Securelist Exploits and vulnerabilities in Q2 2026 CVE-2025-53770

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-53770 9.8 Critical Microsoft SharePoint Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execu…
CVE-2025-49706 6.5 Medium Microsoft SharePoint Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Success…
CVE-2025-53771 6.5 Medium Microsoft Microsoft SharePoint Enterprise Server 2016 Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.