CVE-2025-53770: listed in the CISA KEV catalog

CVE-2025-53770 · CVSS 9.8 CRITICAL · EPSS 100.0% · KEV 2025-07-20

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

Is CVE-2025-53770 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2025-53770

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.