Vulnary
← back to the feed
Critical· 9.8actively exploited

CVE-2025-53770

Microsoft SharePoint Server is vulnerable to a critical deserialization flaw that lets attackers run arbitrary code over the network. The flaw affects on‑premises SharePoint Server 2016 and 2019, and any public‑facing instances that are no longer supported. Microsoft is testing a fix, but users should apply the mitigations outlined by CISA and disconnect unsupported servers.

publishedJul 20, 2025
last modifiedAug 4, 2026
sourcesNVD · CISA-KEV
severity · cvss
9.8
critical · how bad it is
exploitation · epss
100%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 18, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Microsoft SharePoint Server 2016 and 2019 (on‑premises) and any public‑facing SharePoint Server instances that have reached end‑of‑life or end‑of‑service, such as SharePoint 2013 and earlier.

02

Real-world impact

An attacker who can reach the vulnerable SharePoint Server over the network can run arbitrary code, potentially taking full control of the server, accessing sensitive data, and compromising the entire organization.

03

Why this severity

The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication, with no user interaction, and gives attackers complete control over confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
interim mitigations
  • Disconnect public‑facing SharePoint Server instances that are EOL or EOS (e.g., SharePoint 2013 and earlier).
  • For supported SharePoint Server versions, apply the mitigations recommended by CISA and Microsoft.
  • Follow BOD 22‑01 guidance for cloud services or discontinue use if mitigations are not available.
  • Monitor for the release of the comprehensive update from Microsoft.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

CISA KEV required action

05

Timeline

  1. Jul 20, 2025 · Jul 20, 2025
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  2. Jul 20, 2025 · Jul 20, 2025
    Published
    Disclosed and added to the National Vulnerability Database.
  3. Jul 21, 2025 · Jul 21, 2025
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
  4. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →