Critical deserialization vulnerability in on-premises SharePoint Server allowing unauthenticated remote code execution over the network. Actively exploited in the wild with public exploits available.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-07-20
Added to CISA KEV: 2025-07-20 0 DAY BETWEEN CVE AND KEV
Accelerate your learning with Trend Campus, an easy-to-use education platform that offers personalized technical guidance
Microsoft is aware of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the ...
Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and ...
A critical deserialization flaw (CVE-2025-53770) in Microsoft SharePoint Server is being actively exploited, enabling remote code execution by unauthenticated attackers. This post dissects the technical root cause, affected versions, and exploitation vectors for security teams.
CVE-2025-53770 is a critical sharepoint rce flaw actively exploited. Learn about risks, attack vectors, iocs, and patching strategies now.