Product of Microsoft
SharePoint
As of , 10 Microsoft SharePoint vulnerabilities are on CISA's list of exploited vulnerabilities, 5 of them used in ransomware campaigns; 5 were added in 2026. Patch first: CVE-2026-55040.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-55040Weak Authentication | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.70 | ||
| 2 | CVE-2026-58644Deserialization of Untrusted Data | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.16 | ||
| 3 | CVE-2026-50522Deserialization of Untrusted Data | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.03 | ||
| 4 | CVE-2026-65660Code Injection | Microsoft SharePoint | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| 5 | CVE-2025-49704Code Injection | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 6 | CVE-2025-49706Improper Authentication | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 7 | CVE-2025-53770Deserialization of Untrusted Data | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 8 | CVE-2019-0604Remote Code Execution | Microsoft SharePoint | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 9 | CVE-2024-38094Deserialization | Microsoft SharePoint | Patch this weekRansomware use; EPSS 0.51 | 0.51 | ||
| 10 | CVE-2026-20963Deserialization of Untrusted Data | Microsoft SharePoint | Patch soon | 0.30 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 1 |
| 2022 | none |
| 2023 | none |
| 2024 | 1 |
| 2025 | 3 |
| 2026 | 5 |
Used in ransomware
Changes CISA made to these entries
- CVE-2025-53770 Microsoft SharePointRansomware use: Unknown to Known. Edited: required action and description.