Exploited Vulnerabilities Daily
🌐 English

Home › Microsoft

CVE-2024-38094: Microsoft SharePoint

EPSS50.8%No. 863 of 1739 in KEV
CVE year2024listed the same year
Same vendor in KEV389
Same product10
FieldValue
VendorMicrosoft
ProductSharePoint
NameMicrosoft SharePoint Deserialization Vulnerability
Added to KEV2024-10-22
US federal due date2024-11-12
Ransomware useKnown
CWECWE-502

CISA description

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2026-65660Microsoft SharePoint2026-09-252.1%Unknown
CVE-2026-55040Microsoft SharePoint2026-08-1869.5%Unknown
CVE-2026-50522Microsoft SharePoint2026-07-223.0%Unknown
CVE-2026-58644Microsoft SharePoint2026-07-1615.8%Unknown
CVE-2026-20963Microsoft SharePoint2026-03-1829.5%Unknown
CVE-2025-49706Microsoft SharePoint2025-07-2299.0%Known
CVE-2025-49704Microsoft SharePoint2025-07-2299.9%Known
CVE-2025-53770Microsoft SharePoint2025-07-2099.9%Known
CVE-2019-0604Microsoft SharePoint2021-11-0399.9%Known

NVD — CVE-2024-38094

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Microsoft SharePoint vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-22.