Published on: 22 July 2025
 
      
    
         
      
    
Microsoft released a security update to address vulnerabilities in Microsoft SharePoint Server. A remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerabilities.
Reports indicated that the multiple vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771) are being exploited in the wild. Users are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
Successful exploitation of the vulnerabilities could lead to remote code execution, elevation of privilege, information disclosure, security restriction bypass or spoofing on an affected system.
Patches for Microsoft SharePoint Server are available from the Windows Update / Microsoft Update Catalog. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.