logo

Multiple Vulnerabilities in Microsoft SharePoint Server Could Allow for Remote Code Execution

ID: 69e027ea-7a90-5fce-bfa4-a42afffd93ff

STIX ID: report--69e027ea-7a90-5fce-bfa4-a42afffd93ff

Feed Name: CISecurity.org Advisories

Threat Score
78/100

Date Published: 2025-07-22

Date Updated: 2026-04-27

...
...

Multiple critical vulnerabilities in on-premises Microsoft SharePoint Server allow unauthenticated remote code execution and directory traversal/spoofing (CVE-2025-53770, CVE-2025-53771), arising from advanced deserialization and ViewState abuse; these are evolutions of previously incompletely patched flaws and Microsoft released fixes on July 20.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.