← Vulnerability feed

Vulnerability record · CVE-2025-53770 · published 20 July 2025

CVE-2025-53770: Microsoft SharePoint Server deserialization RCE under active exploitation

Microsoft · Sharepoint Server

On-premises Microsoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker run code on the server. Microsoft states an exploit exists in the wild and that a comprehensive update is still in preparation, so defenders must rely on mitigations in the interim. The flaw is critical because it is remotely reachable without credentials and is already being exploited at scale.

9.8 CVSS 3.1 Critical CISA KEV since 20 Jul 2025 Known ransomware use EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References, 3 tagged exploit
4 Aug 2026Last modified by NVD

Description

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network RCE in internet-facing SharePoint with confirmed in-the-wild exploitation, KEV listing, near-certain EPSS score and known ransomware use.

What it is

On-premises Microsoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker run code on the server. Microsoft states an exploit exists in the wild and that a comprehensive update is still in preparation, so defenders must rely on mitigations in the interim. The flaw is critical because it is remotely reachable without credentials and is already being exploited at scale.

Impact

An attacker gains remote code execution on the SharePoint server, which typically means full control of the host and access to connected content, credentials and downstream systems. CISA's KEV entry notes known ransomware campaign use, so follow-on encryption or extortion is a realistic outcome.

Attack surface

Reached over the network against internet-facing on-premises SharePoint Server; the CVSS vector shows no privileges and no user interaction required. No specific endpoint or component is named in the record, so the exact entry point is not stated.

Exploitation

Active exploitation is confirmed: CISA added it to KEV on 2025-07-20 with a 2025-07-21 due date and known ransomware use, EPSS 30-day probability is 0.99998, and multiple references carry Exploit tags.

What to do

  • Apply the Microsoft update as soon as it is released; until then follow the MSRC customer guidance and CISA alert mitigations exactly.
  • Disconnect or isolate internet-facing SharePoint Server instances that are end-of-life or end-of-service, including SharePoint Server 2013 and earlier, per CISA's required action.
  • Restrict or block external access to SharePoint until mitigations are in place, and apply the applicable BOD 22-01 guidance or discontinue use if mitigations are unavailable.
  • Rotate SharePoint machine keys and any credentials or secrets that may have been exposed on affected servers.
  • Review SharePoint servers for signs of prior compromise before restoring normal exposure.

Detection

  • Hunt web server and SharePoint logs for anomalous POST requests or deserialization-related activity from unexpected external sources.
  • Monitor for unexpected child processes spawned by SharePoint worker processes (w3wp.exe), a common post-exploitation signal for web shells.
  • Scan the SharePoint web root and layout directories for newly written or modified files such as web shells.
  • Alert on outbound connections from SharePoint servers to unfamiliar hosts, which may indicate command-and-control or data staging.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-53770 to the Known Exploited Vulnerabilities catalog on 20 July 2025 as "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. Federal deadline 21 July 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-53770 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-20963Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 30%analysed9.8CVE-2023-29357Microsoft SharePoint Server elevation of privilege via authentication bypassCVE-2023-29357 is a critical elevation of privilege flaw in Microsoft SharePoint Server. The CVSS vector shows it is network reachable with no privil…KEVEPSS 100%analysed9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed9.1CVE-2026-55040Microsoft SharePoint weak authentication allows network security feature bypassMicrosoft SharePoint Server contains a weak authentication flaw (CWE-1390) that lets an unauthorized attacker bypass a security feature over the netw…KEVEPSS 18%analysed8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2025-53770), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.