Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since July 22, 2025.

Known ransomware use

CVE-2025-49706

Microsoft SharePoint Improper Authentication Vulnerability

Microsoft · SharePoint

Added to KEV July 22, 2025

Alert details

Source feed
CISA KEV
CVE ID
CVE-2025-49706
CWE
CWE-287
Affected products
SharePoint · Microsoft SharePoint · Microsoft

What happened

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.

What it means for your business

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-49706). Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706. CISA remediation due date: 2025-07-23. If you need help checking exposure, call (864) 335-9223.

Required action

Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CISA due date: July 23, 2025

Sources

Related briefs

Actively exploited (KEV)

CVE-2026-65660

Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-65660). Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. CISA remediation due date: 2026-09-28. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2025-10502

Heap buffer overflow in ANGLE in Microsoft Edge vulnerability

Heap buffer overflow in ANGLE in Microsoft Edge vulnerability (CVE-2025-10502) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-96940

Microsoft Exchange Server Elevation of Privilege vulnerability

Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-96940) was added to Microsoft’s security update guidance. Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49800

Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege vulnerability

Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege vulnerability (CVE-2026-49800) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.