Record summary
A quick snapshot of what this page covers.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2025-49706
- Vendor/project
- Microsoft
- Product
- SharePoint
- Vulnerability name
- Microsoft SharePoint Improper Authentication Vulnerability
- Date added
- 2025-07-22
- Due date
- 2025-07-23
- Known ransomware campaign use
- Known
Exploit context
What the vulnerability is about.
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.
Source
Where this page information comes from.
Original source
Original source links
Open the public records and source datasets used for this page.
