CyberMax
Home › Exploited CVEs › Microsoft

Microsoft SharePoint known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 10 Microsoft SharePoint CVEs as exploited in the wild. 5 were added in the last 12 months and 5 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 10 Microsoft SharePoint CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2025-53770SharePoint Deserialization of Untrusted Data100.00%Yes2025-07-202025-07-21
2CVE-2025-49704SharePoint Code Injection100.00%Yes2025-07-222025-07-23
3CVE-2019-0604SharePoint Remote Code Execution99.91%Yes2021-11-032022-05-03
4CVE-2025-49706SharePoint Improper Authentication99.08%Yes2025-07-222025-07-23
5CVE-2024-38094SharePoint Deserialization50.9%Yes2024-10-222024-11-12
6CVE-2026-20963SharePoint Deserialization of Untrusted Data29.6%–2026-03-182026-03-21
7CVE-2026-55040SharePoint Weak Authentication17.5%–2026-08-182026-08-21
8CVE-2026-58644SharePoint Deserialization of Untrusted Data15.9%–2026-07-162026-07-19
9CVE-2026-50522SharePoint Deserialization of Untrusted Data3.0%–2026-07-222026-07-25
10CVE-2026-65660SharePoint Code Injection2.1%–2026-09-252026-09-28
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Microsoft KEV CVEs · other Microsoft products: Windows · SharePoint Server · Defender · Internet Explorer · Office · Exchange Server · Win32k · free KEV badge for Microsoft · all vendors