On July 19, 2025, Microsoft announced two new vulnerabilities that are actively being exploited (CVE-2025-49704 and CVE-2025-49706) and that relate to on-premises Microsoft SharePoint instances that ...
Update July 22, 2025: Microsoft has updated its blog and advisories, adding a patch for on-premises SharePoint 2016 -- noting again that related vulnerabilities do not affect SharePoint Online in ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert Sunday detailing active exploitation of a critical SharePoint vulnerability, CVE-2025-53770. The zero-day flaw has ...