CVE-2025-53770
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
- Published Jul 20, 2025
- CVSS 9.8 critical
- 100.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
Affected software
In the news
- Warlock ransomware breach SharePoint in water, telecom operator attacks BleepingComputer ·
- Exploits and vulnerabilities in Q2 2026 Securelist ·
- SharpViewStateKing: The stealthy implant framework Canadian Centre for Cyber Security ·
- APT and financial attacks on industrial organizations in Q1 2026 Kaspersky ICS CERT ·
- APT and financial attacks on industrial organizations in Q3 2025 Kaspersky ICS CERT ·