LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-49706: Microsoft SharePoint Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 22, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 23, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-49706 to its Known Exploited Vulnerabilities catalog on Jul 22, 2025, with a federal patch deadline of Jul 23, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view…

CVE-2025-49706 is an improper authentication vulnerability in Microsoft SharePoint that lets an authorized attacker perform spoofing over a network. Successful exploitation can let the attacker view sensitive information and make limited changes to it. The issue is known to be used in ransomware activity, can be chained with CVE-2025-49704, and has a related patch-bypass issue tracked as CVE-2025-53771; teams should treat it as high priority for any exposed SharePoint estate.

Because SharePoint often holds documents, lists, and collaboration data, a successful spoof can expand access or enable further abuse. Confirm all version and patch details against the current Microsoft advisory rather than relying on secondary summaries.

How it works

The weakness is classified as CWE-287 (Improper Authentication). In this class of flaw, authentication checks are incomplete or can be bypassed under certain conditions, allowing an already-authorized attacker to spoof identity or context over the network. The CISA summary states that successful exploitation of CVE-2025-49706 can permit viewing of sensitive information and some modification of disclosed data.

Public detail does not describe the exact request sequence or protocol fields involved; defenders should not invent exploit mechanics. The vulnerability can be chained with CVE-2025-49704. Separately, CVE-2025-53771 is described as a patch bypass for CVE-2025-49706, and the updates that address CVE-2025-53771 provide more robust protection than the earlier fixes for CVE-2025-49706 alone. Any technical investigation should therefore start from the latest vendor security update rather than older patches.

Am I affected? How to find it in your systems

Microsoft SharePoint is commonly deployed as on-premises SharePoint Server (often behind reverse proxies or load balancers) and may also appear in hybrid configurations. Inventory every SharePoint farm, web application, and site collection that is reachable from untrusted networks.

Exact affected version ranges and configuration prerequisites are not fully enumerated in the supplied facts; always verify against the vendor advisory before declaring a system safe.

How to remediate

Apply the Microsoft security updates that address both CVE-2025-49706 and the more robust protections included for the patch-bypass CVE-2025-53771. Prefer the latest cumulative update that Microsoft identifies as containing the complete fix set.

If you can't patch immediately

Until the vendor updates can be installed, reduce exposure with compensating controls that limit network reachability and increase detection.

If your data may have been exposed

Actively exploited vulnerabilities of this class, especially those with known ransomware use, frequently lead to data theft or encryption. If SharePoint content or credentials may have been accessed, treat the incident as a potential breach: isolate affected systems, preserve logs, and begin containment and recovery according to your incident-response plan. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-287
Added to CISA KEVJul 22, 2025
Federal patch deadlineJul 23, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities