LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-53770: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 20, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 21, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-53770 to its Known Exploited Vulnerabilities catalog on Jul 20, 2025, with a federal patch deadline of Jul 21, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be…

CVE-2025-53770 is a deserialization of untrusted data vulnerability in Microsoft SharePoint Server on-premises. An unauthorized attacker can use it to execute code over the network. It matters because it is a known ransomware vector, can be chained with CVE-2025-53771, and acts as a patch bypass for the earlier CVE-2025-49704; the updates for this CVE supply more robust protection than those earlier fixes. Confirm all product and version details against the current Microsoft advisory.

How it works

The weakness is CWE-502: deserialization of untrusted data. SharePoint Server processes serialized objects that an attacker can influence. When the application deserializes that data without adequate validation, the attacker can cause the runtime to instantiate unexpected types or invoke methods that lead to remote code execution. Because the flaw is reachable over the network by an unauthorized party, successful abuse can give the attacker the ability to run code in the context of the SharePoint process. Public detail on exact gadget chains or request formats is limited; treat any claimed exploit mechanics as unconfirmed until verified against the vendor advisory. The same advisory notes that this CVE can be chained with CVE-2025-53771 and that prior patches for CVE-2025-49704 were incomplete.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft SharePoint Server on-premises installations. Cloud-hosted SharePoint Online is outside the scope described by CISA for this CVE, but organizations should still confirm their exact deployment model. Typical locations include internal collaboration farms, extranet portals, and any public-facing SharePoint sites that have not been retired.

Specific version ranges and detection signatures must be confirmed against the vendor advisory and CISA guidance.

How to remediate

Apply the Microsoft security update that specifically addresses CVE-2025-53770; the vendor states these updates include more robust protection than the earlier fixes for CVE-2025-49704. After patching, restart the affected services and verify the new build number in Central Administration or via PowerShell.

If you can't patch immediately

Reduce exposure while preparing the official update.

If your data may have been exposed

Actively exploited vulnerabilities of this class, especially those with confirmed ransomware use, frequently lead to full farm compromise, data theft, and encryption. Assume that any unpatched, network-reachable SharePoint Server could have been abused. Review access logs, check for unauthorized file downloads or modifications, and rotate credentials for service accounts and farm administrators. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether related credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-502
Added to CISA KEVJul 20, 2025
Federal patch deadlineJul 21, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities