CVE-2025-49706 is an improper authentication vulnerability in Microsoft SharePoint Server that allows network-based spoofing attacks without authentication. The vulnerability is actively exploited in the wild and enables attackers to bypass authentication by manipulating HTTP headers.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-07-08
Added to CISA KEV: 2025-07-22 14 DAYS BETWEEN CVE AND KEV
Active attacks are targeting on-premises SharePoint Server customers by exploiting a variant of CVE-2025-49706. This new variant has been ...
CVEโ2025โ49706, a spoofing vulnerability in SharePoint Server, has evolved from medium-severity to real-world weaponization, with a variant (CVEโ2025โ53770) now actively exploited in the wild.
A deep dive into CVE-2025-49706 โ the SharePoint spoofing flaw now exploited in the wild for stealthy web shell deployment and privilege escalation.
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Metrics. CVSS Version 4.0. CVSS ...
CVE-2025-49706: An authentication bypass (spoofing) vulnerability that allows unauthenticated attackers to access restricted SharePoint functionality. Attackers manipulate HTTP requests to the /ToolPane.aspx, specifically, by forging the Referer header.