peter bassill · operator
$ cve CVE-2025-53770 JSON

CVE-2025-53770 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-07-21.

Description

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2025-07-21
Public exploityes
Published2025-07-20
Last modified2026-08-04

CISA KEV

NameMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability
Added2025-07-20
Due2025-07-21
Vendor / productMicrosoft / SharePoint
Ransomware useknown

Affected (1)

VendorProduct
microsoftsharepoint server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD