← Back to CVE List
Vulnerability Intelligence Report
Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2025-53770

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable Deserialization
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:99.98%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-502 ↗CWE-502: Deserialization of Untrusted Data

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 < 16.0.5513.1001 (affected)
Microsoft Microsoft SharePoint Server 2019 16.0.0 < 16.0.10417.20037 (affected)
Microsoft Microsoft SharePoint Server Subscription Edition 16.0.0 < 16.0.18526.20508 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.979%
Vulnerability Class
Deserialization

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2025-07-09T13:25:25
Published2025-07-20T01:06:33
Patch Date2025-07-19
Last Updated2026-08-04T03:55:52

LINK COPIED TO CLIPBOARD