Exploited Vulnerabilities Daily
🌐 English

Home › Microsoft

CVE-2025-53770: Microsoft SharePoint

EPSS99.9%No. 41 of 1739 in KEV
CVE year2025listed the same year
Same vendor in KEV389
Same product10
FieldValue
VendorMicrosoft
ProductSharePoint
NameMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability
Added to KEV2025-07-20
US federal due date2025-07-21
Ransomware useKnown
CWECWE-502

CISA description

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2026-65660Microsoft SharePoint2026-09-252.1%Unknown
CVE-2026-55040Microsoft SharePoint2026-08-1869.5%Unknown
CVE-2026-50522Microsoft SharePoint2026-07-223.0%Unknown
CVE-2026-58644Microsoft SharePoint2026-07-1615.8%Unknown
CVE-2026-20963Microsoft SharePoint2026-03-1829.5%Unknown
CVE-2025-49706Microsoft SharePoint2025-07-2299.0%Known
CVE-2025-49704Microsoft SharePoint2025-07-2299.9%Known
CVE-2024-38094Microsoft SharePoint2024-10-2250.8%Known
CVE-2019-0604Microsoft SharePoint2021-11-0399.9%Known

NVD — CVE-2025-53770

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Microsoft SharePoint vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-20.