Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
CVE-2025-53770
Score elevated to 9.8 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2025-07-20), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EG Risk
- 99(Act)EG Risk 99/100SSVC: Act
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation100% × 40%Automatability100% × 15%Action: Fix now — active exploitation, automatable, high impact. - EPSS
- 100.0%
- KEV
- ⚠ Exploited
Published
July 20, 2025
Last Modified
October 27, 2025
Advisory Details (10)
Auto-updated Jun 1, 2026Microsoft Rushes Emergency Fix for Exploited SharePoint Bug
https://www.darkreading.com/remote-workforce/microsoft-rushes-emergency-fix-exploited-sharepoint-toolshell-flawUPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities | CISA
UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
https://www.bleepingcomputer.com/news/microsoft/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available/Warnings issued as hackers actively exploit critical zero-day in Microsoft SharePoint | The Record from Recorded Future News
https://therecord.media/microsoft-sharepoint-zero-day-vulnerability-exploited-globallySharePoint Under Siege: ToolShell Exploit (CVE-2025-49706 & CVE-2025-49704) - Eye Research
https://research.eye.security/sharepoint-under-siege/Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say | Hacker News
https://news.ycombinator.com/item?id=44629710Microsoft Security Response Center Blog
Microsoft Security Response Center Blog. Patch available via Microsoft Security Update
Affected: Windows 11 apps_nav", "ecn": "FooterNav_Whats_New_Footer_WhatsNew_Windows_11_apps_nav"
https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/GitHub - kaizensecurity/CVE-2025-53770: POC · GitHub
https://github.com/kaizensecurity/CVE-2025-53770SharePoint vulnerability with 9.8 severity rating under exploit across globe - Ars Technica
https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/Security Update Guide - Microsoft Security Response Center
Security Update Guide - Microsoft Security Response Center. Patch available via Microsoft Security Update
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(1)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Data Freshness Timeline
(refreshed 53× in last 7d / 327× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 645 total refreshes for this CVE.
- 2026-07-23 02:58 UTCEG score recompute
- 2026-07-23 00:01 UTCEG score recompute
- 2026-07-23 00:01 UTCVendor advisory
- 2026-07-23 00:01 UTCGHSA enrichment
- 2026-07-22 19:55 UTCGHSA enrichment
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 15:47 UTCVendor advisory
- 2026-07-22 15:47 UTCGHSA enrichment
- 2026-07-22 11:40 UTCVendor advisory
- 2026-07-22 11:40 UTCGHSA enrichment
- 2026-07-22 07:34 UTCVendor advisory
- 2026-07-22 07:34 UTCGHSA enrichment
- 2026-07-22 03:28 UTCVendor advisory
- 2026-07-22 03:28 UTCGHSA enrichment
- 2026-07-21 23:20 UTCVendor advisory
- 2026-07-21 23:20 UTCGHSA enrichment
- 2026-07-21 17:42 UTCEG score recompute
- 2026-07-21 17:42 UTCVendor advisory
- 2026-07-21 17:42 UTCGHSA enrichment
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 13:35 UTCVendor advisory
- 2026-07-21 13:35 UTCGHSA enrichment
- 2026-07-21 09:29 UTCVendor advisory
- 2026-07-21 09:28 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-07-21 05:22 UTCVendor advisory
- 2026-07-21 05:21 UTCGHSA enrichment
- 2026-07-21 01:14 UTCVendor advisory
- 2026-07-21 01:14 UTCGHSA enrichment
- 2026-07-20 21:08 UTCVendor advisory
- 2026-07-20 21:07 UTCGHSA enrichment
- 2026-07-20 17:00 UTCVendor advisory
- 2026-07-20 16:59 UTCGHSA enrichment
- 2026-07-20 12:53 UTCGHSA enrichment
- 2026-07-20 08:47 UTCVendor advisory
- 2026-07-20 08:47 UTCGHSA enrichment
- 2026-07-20 04:41 UTCVendor advisory
- 2026-07-20 04:41 UTCGHSA enrichment
- 2026-07-20 00:35 UTCVendor advisory
- 2026-07-20 00:35 UTCGHSA enrichment
- 2026-07-19 20:28 UTCVendor advisory
- 2026-07-19 20:28 UTCGHSA enrichment
- 2026-07-19 16:22 UTCVendor advisory
- 2026-07-19 16:22 UTCGHSA enrichment
- 2026-07-19 12:15 UTCVendor advisory
- 2026-07-19 12:15 UTCGHSA enrichment
- 2026-07-19 08:06 UTCVendor advisory
- 2026-07-19 08:06 UTCGHSA enrichment
- 2026-07-19 04:00 UTCVendor advisory
- 2026-07-19 04:00 UTCGHSA enrichment
- 2026-07-18 23:54 UTCGHSA enrichment
- 2026-07-18 19:48 UTCVendor advisory
- 2026-07-18 19:48 UTCGHSA enrichment
- 2026-07-18 15:42 UTCVendor advisory
- 2026-07-18 15:42 UTCGHSA enrichment
- 2026-07-18 11:36 UTCVendor advisory
- 2026-07-18 11:36 UTCGHSA enrichment
- 2026-07-18 07:30 UTCVendor advisory
- 2026-07-18 07:30 UTCGHSA enrichment
- 2026-07-18 03:24 UTCVendor advisory
- 2026-07-18 03:24 UTCGHSA enrichment
- 2026-07-17 23:18 UTCVendor advisory
- 2026-07-17 23:18 UTCGHSA enrichment
- 2026-07-17 19:11 UTCVendor advisory
- 2026-07-17 19:11 UTCGHSA enrichment
- 2026-07-17 15:05 UTCVendor advisory
- 2026-07-17 15:05 UTCGHSA enrichment
- 2026-07-17 10:59 UTCVendor advisory
- 2026-07-17 10:59 UTCGHSA enrichment
- 2026-07-17 06:53 UTCVendor advisory
- 2026-07-17 06:53 UTCGHSA enrichment
- 2026-07-17 02:47 UTCVendor advisory
- 2026-07-17 02:47 UTCGHSA enrichment
- 2026-07-16 22:41 UTCVendor advisory
- 2026-07-16 22:41 UTCGHSA enrichment
- 2026-07-16 18:34 UTCGHSA enrichment
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 14:28 UTCVendor advisory
- 2026-07-16 14:28 UTCGHSA enrichment
- 2026-07-16 10:22 UTCVendor advisory
- 2026-07-16 10:22 UTCGHSA enrichment
- 2026-07-16 06:16 UTCVendor advisory
- 2026-07-16 06:15 UTCGHSA enrichment
- 2026-07-16 02:09 UTCVendor advisory
- 2026-07-16 02:09 UTCGHSA enrichment
- 2026-07-15 22:03 UTCVendor advisory
- 2026-07-15 22:02 UTCGHSA enrichment
- 2026-07-15 17:56 UTCVendor advisory
- 2026-07-15 17:56 UTCGHSA enrichment
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 13:49 UTCVendor advisory
- 2026-07-15 13:49 UTCGHSA enrichment
- 2026-07-15 09:42 UTCVendor advisory
- 2026-07-15 09:41 UTCGHSA enrichment
- 2026-07-15 05:35 UTCVendor advisory
- 2026-07-15 05:35 UTCGHSA enrichment
- 2026-07-15 01:28 UTCGHSA enrichment
- 2026-07-14 21:22 UTCVendor advisory
- 2026-07-14 21:22 UTCGHSA enrichment
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Open source ↗GitHub PoCsaladin0x1/CVE-2025-53770First seen Sep 4, 2025
- Exploit-DBEDB-52405First seen Aug 11, 2025
Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
Open source ↗ - Open source ↗GitHub PoCImmersive-Labs-Sec/SharePoint-CVE-2025-53770-POCFirst seen Jul 29, 2025
- GitHub PoC3a7/CVE-2025-53770First seen Jul 27, 2025
CVE-2025-53770 Mass Scanner
Open source ↗ - GitHub PoCexfil0/CVE-2025-53770First seen Jul 23, 2025
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition)
Open source ↗ - GitHub PoCMuhammadWaseem29/CVE-2025-53770First seen Jul 22, 2025
Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)
Open source ↗ - GitHub PoCAdityaBhatt3010/CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCEFirst seen Jul 22, 2025
A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706.
Open source ↗ - GitHub PoCkaizensecurity/CVE-2025-53770First seen Jul 21, 2025
POC
Open source ↗ - GitHub PoCsoltanali0/CVE-2025-53770-ExploitFirst seen Jul 21, 2025
SharePoint WebPart Injection Exploit Tool
Open source ↗ - GitHub PoChazcod/CVE-2025-53770First seen Jul 21, 2025
Scanner for the SharePoint CVE-2025-53770 RCE zero day vulnerability.
Open source ↗
Related CVEs(same vendor + same CWE)
Same vendor
10 shownmsrc
- CVE-2006-10003EG 9.8CRITICAL
- CVE-2015-20107NVD 7.6EG 9.8EPSS 94%HIGH
- CVE-2013-7381EG 9.8CRITICAL
- CVE-2014-0048EG 9.8EPSS 93%CRITICAL
- CVE-2007-4559EG 9.8EPSS 98%CRITICAL
- CVE-2013-3900NVD 5.5EG 9.0 KEVEPSS 99%MEDIUM
- CVE-2013-2094NVD 8.4EG 9.0 KEVEPSS 99%HIGH
- CVE-2014-9356EG 8.6EPSS 91%HIGH
- CVE-2014-5282EG 8.1HIGH
- CVE-2014-8141EG 7.8EPSS 94%HIGH
Same CWE
10 shownCWE-502
- CVE-2017-20208EG 9.8CRITICAL
- CVE-2017-20207EG 9.8CRITICAL
- CVE-2017-20206EG 9.8CRITICAL
- CVE-2017-20189EG 9.8CRITICAL
- CVE-2017-10992EG 9.8EPSS 95%CRITICAL
- CVE-2013-4521EG 9.8EPSS 90%CRITICAL
- CVE-2014-1860EG 9.8CRITICAL
- CVE-2016-1000027EG 9.8EPSS 98%CRITICAL
- CVE-2014-3699EG 9.8CRITICAL
- CVE-2017-18605EG 9.8CRITICAL
Frequently asked(6)
What is CVE-2025-53770?
When was CVE-2025-53770 disclosed?
Is CVE-2025-53770 actively exploited?
What is the CVSS score of CVE-2025-53770?
Which products are affected by CVE-2025-53770?
How do I remediate CVE-2025-53770?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2025-53770
Is Your Infrastructure Affected by CVE-2025-53770?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.