CyberMax
Home › Exploited CVEs › Microsoft

Microsoft SharePoint Server known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 5 Microsoft SharePoint Server CVEs as exploited in the wild. 3 were added in the last 12 months and 3 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 5 Microsoft SharePoint Server CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2023-29357SharePoint Server Privilege Escalation99.98%Yes2024-01-102024-01-31
2CVE-2023-24955SharePoint Server Code Injection85.0%Yes2024-03-262024-04-16
3CVE-2026-32201SharePoint Server Improper Input Validation43.4%–2026-04-142026-04-28
4CVE-2026-45659SharePoint Server Deserialization of Untrusted Data2.7%Yes2026-07-012026-07-04
5CVE-2026-56164SharePoint Server Missing Authentication for Critical Function1.0%–2026-07-142026-07-17
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Microsoft KEV CVEs · other Microsoft products: SharePoint · Windows · Defender · Internet Explorer · Office · Exchange Server · Win32k · free KEV badge for Microsoft · all vendors