Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks
On Sunday, Microsoft published security updates for a SharePoint vulnerability that was being actively exploited. The company also revealed information on another vulnerability that it said had been fixed with stronger safeguards.
The IT behemoth admitted that it is aware of ongoing attacks that take advantage of flaws that the July Security Update only partially fixed and target users of on-premises SharePoint Server.
As the exploited vulnerability is recorded, CVE-2025-53770 (CVSS score: 9.8) relates to a situation of remote code execution that occurs when untrusted data is deserialized in on-premise versions of Microsoft SharePoint Server.
The recently revealed vulnerability is a SharePoint spoofing vulnerability (CVE-2025-53771, CVSS score: 6.3). The bug has been identified a...










