CVE-2025-49706CISA KEV
Microsoft SharePoint Improper Authentication Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.
- Product
- SharePoint
- Added to KEV
- 22 Jul 2025
- Federal remediation due
- 23 Jul 2025
- Known ransomware use
- Yes