CVE-2025-53770CISA KEV
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
- Product
- SharePoint
- Added to KEV
- 20 Jul 2025
- Federal remediation due
- 21 Jul 2025
- Known ransomware use
- Yes