SharePoint Vulnerability 07/2025
Our experts keep you up-to-date on critical cyber threats (CVEs)
Microsoft recently discovered two critical vulnerabilities in on-premises SharePoint Servers
SharePoint Vulnerability 07/2025
Microsoft recently discovered two critical vulnerabilities in on-premises SharePoint Servers: CVE-2025-53770 and CVE-2025-53771. These vulnerabilities are currently being actively exploited and require urgent action for organisations hosting SharePoint locally.
Take action
Important to know
- These vulnerabilities apply only for on-premises SharePoint Servers. SharePoint Online in Microsoft 365 is unaffected.
- The updates are cumulative: you don't need to install previous updates separately if you apply the latest one.
- Microsoft has also published detection and hunting queries for use in Microsoft Defender
It is crucial that organisations using SharePoint Server 2016, 2019 or the Subscription Edition, immediately apply the latest security updates.
✅ What to do?
- Update to a supported version of SharePoint Server (2016, 2019 or Subscription Edition).
- Install the July 2025 security updates
- Activate AMSI (Antimalware Scan Interface) and ensure correct configuration with an antivirus solution such as Microsoft Defender Antivirus.
- Run the ASP.NET machine keys again and restart IIS on all SharePoint servers.
- Deploy Microsoft Defender for Endpoint or an equivalent solution for detection of post-exploit activities.
Can't create tickets? Ask here to get an account. If our Engineer needs to remotely control your PC, he or she will ask you to run this software .