References https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/ https://www.microsoft.com/en-us/msrc/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770 https://nvd.nist.gov/vuln/detail/CVE-2025-53770 https://unit42.paloaltonetworks.com/zh-hant/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/ https://www.trendmicro.com/zh_tw/research/25/g/cve-2025-53770-and-cve-2025-53771-sharepoint-attacks.html https://www.cisa.gov/news-events/alerts/2025/07/20/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities https://www.secrss.com/articles/81107 https://www.twcert.org.tw/tw/cp-169-10277-e0fc0-1.html https://research.eye.security/sharepoint-under-siege/
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page DisclosurePoCsharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata DisclosurePoCsharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages DisclosurePoCCVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass(CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行