CVE-2025-53770
Microsoft SharePoint Server is vulnerable to a critical deserialization flaw that lets attackers run arbitrary code over the network. The flaw affects on‑premises SharePoint Server 2016 and 2019, and any public‑facing instances that are no longer supported. Microsoft is testing a fix, but users should apply the mitigations outlined by CISA and disconnect unsupported servers.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Microsoft SharePoint Server 2016 and 2019 (on‑premises) and any public‑facing SharePoint Server instances that have reached end‑of‑life or end‑of‑service, such as SharePoint 2013 and earlier.
Real-world impact
An attacker who can reach the vulnerable SharePoint Server over the network can run arbitrary code, potentially taking full control of the server, accessing sensitive data, and compromising the entire organization.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication, with no user interaction, and gives attackers complete control over confidentiality, integrity, and availability.
What to do about it
- ›Disconnect public‑facing SharePoint Server instances that are EOL or EOS (e.g., SharePoint 2013 and earlier).
- ›For supported SharePoint Server versions, apply the mitigations recommended by CISA and Microsoft.
- ›Follow BOD 22‑01 guidance for cloud services or discontinue use if mitigations are not available.
- ›Monitor for the release of the comprehensive update from Microsoft.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
CISA KEV required action
Timeline
- Jul 20, 2025 · Jul 20, 2025Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 20, 2025 · Jul 20, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2025 · Jul 21, 2025CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- msrc.microsoft.com/update-guide/vulnerability/…vendor advisory
- arstechnica.com/security/2025/07/sharepoint…exploitpress/media coverage
- github.com/kaizensecurity/CVE-2025-537…exploit
- msrc.microsoft.com/blog/2025/07/customer-guida…mitigationvendor advisory
- news.ycombinator.com/itemissue tracking
- research.eye.security/sharepoint-under-siege/exploitmitigationthird party advisory
- therecord.media/microsoft-sharepoint-zero-d…press/media coverage
- bleepingcomputer.com/news/microsoft/microsoft-sh…press/media coverage
- cisa.gov/news-events/alerts/2025/07/…mailing listthird party advisoryus government resource
- darkreading.com/remote-workforce/microsoft-…press/media coverage
- forbes.com/sites/daveywinder/2025/07/2…press/media coverage
- x.com/Shadowserver/status/1946900…third party advisory
- cisa.gov/known-exploited-vulnerabili…us government resource