CISA has issued an urgent warning about a critical zero-day remote code execution vulnerability affecting Microsoft SharePoint Server on-premises installations that threat actors are actively exploiting in the wild. The vulnerability, tracked as CVE-2025-53770, poses a significant security risk to organizations running SharePoint infrastructure and has prompted immediate action requirements from federal agencies, as well as recommendations for all affected organizations. The vulnerability allows unauthorized attackers to execute arbitrary code remotely over a network connection, making it particularly dangerous for organizations with internet-facing SharePoint deployments. For organizations unable to implement AMSI integration, CISA recommends the more drastic measure of immediately disconnecting affected public-facing SharePoint products from internet access until official mitigations become available. The newly discovered vulnerability, CVE-2025-53770, stems from a deserialization of untrusted data flaw within Microsoft SharePoint Server on-premises environments. This type of vulnerability is especially concerning because it can be exploited remotely without requiring authentication, depending on the specific configuration and exposure of the SharePoint server. CISA added CVE-2025-53770 to its Known Exploited Vulnerabilities catalog on July 20, 2025, with an extremely tight remediation deadline of July 21, 2025, indicating the severity and active exploitation of this vulnerability. Organizations with public-facing SharePoint servers are at the highest risk, as these systems can be directly targeted from the internet without requiring initial network compromise. While it remains unknown whether this vulnerability is being leveraged in ransomware campaigns, the rapid timeline for remediation suggests that CISA has observed credible threat activity targeting this specific flaw. CVE-2025-53770 allows remote code execution on SharePoint servers and is actively exploited in the wild.
This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 21 Jul 2025 12:00:18 +0000