CVE-2025-49706

Microsoft SharePoint: Improper Authentication

As of , CVE-2025-49706 in Microsoft SharePoint is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 22 July 2025
US federal deadline
23 July 20251 day after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
KnownCISA changed it from Unknown to Known on 24 July 2025.
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
1 Metasploit module
Fix
Vendor advice: msrc.microsoft.com and www.microsoft.comLinks below, from CISA's entry.

What CISA says to do

Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CISA's required action

What the flaw is

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.

CISA's description

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

The CVE record's description, from microsoft

CVE published
8 July 2025
Assigned by
microsoft
CVSS
6.5 Medium (CVSS 3.1, from the CNA)
CWE-287
Improper Authentication
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
partial

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. CISA changed its entry. Ransomware use: Unknown to Known.
  5. CISA changed its entry. Edited: notes.
  6. CISA changed its entry. Edited: required action and description.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

SharePoint: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-55040Weak AuthenticationMicrosoft SharePointPatch nowForensic triage required by CISA0.70
CVE-2026-58644Deserialization of Untrusted DataMicrosoft SharePointPatch nowForensic triage required by CISA0.16
CVE-2026-50522Deserialization of Untrusted DataMicrosoft SharePointPatch nowForensic triage required by CISA0.03
CVE-2026-65660Code InjectionMicrosoft SharePointPatch nowForensic triage required by CISA; listed in the last 14 days0.02
CVE-2025-49704Code InjectionMicrosoft SharePointPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-53770Deserialization of Untrusted DataMicrosoft SharePointPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2019-0604Remote Code ExecutionMicrosoft SharePointPatch this weekRansomware use; EPSS 0.990.99
CVE-2024-38094DeserializationMicrosoft SharePointPatch this weekRansomware use; EPSS 0.510.51
CVE-2026-20963Deserialization of Untrusted DataMicrosoft SharePointPatch soon0.30

Read further