CVE-2025-49704CISA KEV
Microsoft SharePoint Code Injection Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
- Product
- SharePoint
- Added to KEV
- 22 Jul 2025
- Federal remediation due
- 23 Jul 2025
- Known ransomware use
- Yes