CVE-2025-53770 and CVE-2025-53771: Actively Exploited SharePoint Vulnerabilities

July 22, 2025, 9:29 a.m.

Description

Two critical vulnerabilities, CVE-2025-53770 and CVE-2025-53771, are affecting Microsoft SharePoint Servers, enabling attackers to upload malicious files and extract cryptographic secrets. These flaws are evolutions of previously patched vulnerabilities, CVE-2025-49704 and CVE-2025-49706, which were incompletely remediated. Exploit attempts have been observed across various industries, including finance, education, energy, and healthcare. Microsoft has released patches for SharePoint Subscription Edition and Server 2019, with a patch for Server 2016 pending. The vulnerabilities allow for unauthenticated remote code execution through advanced deserialization techniques and ViewState abuse. Active exploitation in the wild has been confirmed, compromising on-premises SharePoint environments globally.

Date

  • Created: July 22, 2025, 9:04 a.m.
  • Published: July 22, 2025, 9:04 a.m.
  • Modified: July 22, 2025, 9:29 a.m.

Indicators

  • b336f936be13b3d01a8544ea3906193608022b40c28dd8f1f281e361c9b64e93
  • 27c45b8ed7b8a7e5fff473b50c24028bd028a9fe8e25e5cea2bf5e676e531014
  • 92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514
  • 8d3d3f3a17d233bc8562765e61f7314ca7a08130ac0fb153ffd091612920b0f2
  • 96.9.125.147
  • 104.238.159.149
  • 107.191.58.76
  • 103.186.30.186

Additional Informations

  • Healthcare
  • Energy
  • Education
  • Finance

Linked vulnerabilities