CVE-2025-49706General(microsoft / sharepoint_enterprise_server)

MEDIUMCVSS 6.5 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft sharepoint_enterprise_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-23. Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_enterprise_server
  • sharepoint_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • 11 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Technical details provided in 2 signals
  • General: 4 classified signals
  • Peaked 6d ago at 2 mentions (2026-06-20); latest day: 1
  • 11 total mentions across 9 days

Affected systems

Vendors
Products
sharepoint_enterprise_serversharepoint_server

2 versions affected across 2 products

Deep dive

Activity timeline11 mentions / 9d
01122Mentions · 2026-04-08: 1Mentions · 2026-04-14: 1Mentions · 2026-06-20: 2Mentions · 2026-06-21: 1Mentions · 2026-07-23: 1Mentions · 2026-10-01: 1Mentions · 2026-10-02: 2Mentions · 2026-10-04: 1Mentions · 2026-10-05: 1Exploit Tool / Code · 2026-07-23: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-07-23: 1Technical Details · 2026-06-21: 1Technical Details · 2026-07-23: 104-0804-1406-2006-2107-2310-0110-0210-0410-05
Signal classification2 categories
General
466.7%
Active Exploitation
233.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-081
Active Exploitation1
2026-04-141
General1
2026-06-202
General2
2026-06-211
General1
2026-07-231
Active Exploitation1
Full discourse11 posts
  • kmkz@kmkz_security
    General

    The 401 That Fooled Me N-Day Review of CVE-2025-49706 in SharePoint https://y4nush.com/posts/the-401-that-fooled-me-n-day-review-of-cve-2025-49706-in-sharepoint/

    Post summary

    The provided snippet merely announces a review of CVE‑2025‑49706 in SharePoint, without offering explicit technical details, PoC, exploit, patch, or evidence of active exploitation. Hence it falls into the General category with low confidence for any specific indicators.

    118072344.2K
    19.7K followersView on X
  • Nicolas Krassas@Dinosn
    General

    The 401 That Fooled Me - N-Day Review of CVE-2025-49706 in SharePoint https://y4nush.com/posts/the-401-that-fooled-me-n-day-review-of-cve-2025-49706-in-sharepoint/

    Post summary

    The provided text appears to be a general review article title for CVE-2025-49706 in SharePoint, without indication of PoC, exploit code, active attacks, patches, or detailed technical information.

    04025142.6K
    159.6K followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet lists the top 25 CVEs that have evidence of exploitation attempts, indicating active usage in the wild, but provides no PoC, tool details, or mitigation information.

    070921.2K
    5.5K followersView on X
  • Machina Record@MachinaRecord

    🚨Warlockランサムウェアが引き続きToolShell悪用、重要インフラに攻撃を拡大(CVE-2025-49704、CVE-2025-49706) ⚠️GitLab、AIゲートウェイサービスにおける重大なRCEの脆弱性について警告:CVE-2026-90970 〜サイバーセキュリティ週末の話題〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47913/

    00011344
    1.3K followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — WARLOCK RANSOMWARE CAMPAIGN HITS WATER AND TELECOM OPERATORS THROUGH SHAREPOINT October 1, 2026 DISCLOSED BY: Symantec / Carbon Black CONFIRMED EXPLOITED BY: Symantec / Carbon Black PRODUCT: Microsoft SharePoint Server — On-Premises CVE: Multiple SharePoint vulnerabilities are used across the campaign. Historically associated ToolShell flaws include CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. IMPACT: Symantec documented a recent Warlock campaign compromising at least four organizations, including a water utility and telecommunications provider, plus a regional government body and university. In one critical-infrastructure intrusion, attackers disabled security tooling on at least 40 hosts in roughly two hours and deployed Warlock ransomware to at least 33 systems through the domain SYSVOL share. EXPLOITATION STATUS: CONFIRMED OPERATIONAL RANSOMWARE CAMPAIGN CISA records knownRansomwareCampaignUse: Known for the core ToolShell KEV entries CVE-2025-49704, CVE-2025-49706 and CVE-2025-53770. The exact SharePoint CVE used for every recent intrusion has NOT been established. Attribution: Symantec tracks the actor as Longlegs, also associated with Storm-2603, and assesses it as China-nexus. This is NOT a formal government attribution to the Chinese state. Forensic triage: Hunt for SharePoint LAYOUTS web shells, stolen http://ASP.NET machine keys, K7RKScan/BYOVD activity, Visual Studio Code tunnels, NetExec, suspicious SYSVOL payloads and domain-wide ransomware staging. URGENT ACTION: Patch all on-premises SharePoint servers. Previously exposed systems require compromise assessment, http://ASP.NET machine-key rotation, credential review, and hunting across SYSVOL and domain controllers; patching alone does not establish that the environment is clean. SOURCE: https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json?utm_source=chatgpt.com CONFIDENCE: VERY HIGH for the campaign, victim scope and observed post-exploitation behavior based on direct Symantec/Carbon Black investigations. The China-nexus attribution is a vendor intelligence assessment, not a formal government attribution. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #ToolShell #Warlock #Storm2603 #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics

    00010129
    226 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Microsoft DART investigated a ransomware breach of on-premises SharePoint servers where two separate threat actors were found operating simultaneously, exploiting CVE-2025-49706 and CVE-2025-49704. Key findings: - Storm-2603, assessed as China-based, exploited CVE-2025-49706 (SharePoint auth spoofing) and CVE-2025-49704 (SharePoint code injection) to gain initial access, then used Velociraptor at SYSTEM-level for recon, blending into trusted admin behavior. Remote access was maintained via Cloudflare tunneling, Zoho Assist, and SSH through Visual Studio Code, followed by new local and domain admin account creation. - A second, unidentified threat actor operated concurrently in the same environment using DLL sideloading into legitimate Windows processes and custom backdoors, neither linked to Storm-2603. The layered activity from two actors obscured each other, complicating attribution and timeline reconstruction. - The driver NSecKrnl.sys was loaded to tamper with memory and disable endpoint protections before subsequent activity, a classic BYOVD move that blind-spots EDR before the heavier tooling arrives. - DART confirmed at least two victim organizations through lateral movement forensics, and any unpatched internet-facing SharePoint server remains exposed. #DFIR_Radar

    Post summary

    Two distinct threat actors actively exploited recent SharePoint CVEs using sophisticated tooling, revealing ongoing compromise and emphasizing the need for timely patching.

    10000200
    1.8K followersView on X
  • SecureChap@SecureChap

    Warlock ransomware operators chained four SharePoint CVEs for domain access on July 22. Unspecified on-prem builds were hit with CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 via ToolShell. Microsoft linked the same chain to Linen Typhoon, Violet Typhoon, and Storm-2603. Within two hours the operators dropped an AV/EDR killer to 40 hosts via BYOVD. They abused the signed K7RKScan.sys driver through CVE-2025-1055 to load a malicious kernel module and disable protections, then deployed a multi-version SharePoint web shell for persistence. NetExec handled AD enumeration and spraying while VS Code Insiders ran as a service for tunneling. Ransomware binaries were staged in the domain SYSVOL share for GPO and logon script distribution. Artifacts were deleted two days later. Warlock executed on 33 hosts by July 31 against a water utility, telecom provider, regional government, and university in Portuguese- and Spanish-speaking regions. Symantec attributes the activity to Longlegs. BYOVD via K7RKScan plus SYSVOL staging turned SharePoint access into domain-wide execution in under ten days.

    0000061
    175 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — WARLOCK RANSOMWARE ACTORS CONTINUE EXPLOITING SHAREPOINT, HITTING WATER AND TELECOM OPERATORS October 1, 2026 DISCLOSED BY: Symantec / Broadcom Threat Hunter Team CONFIRMED EXPLOITED BY: Longlegs / Storm-2603 PRODUCT: Microsoft SharePoint Server — On-Premises CVE: No single CVE is publicly confirmed for every recent intrusion. Historically associated ToolShell chain: CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 IMPACT: SharePoint exploitation → web shell → http://ASP.NET Machine Key theft → code execution → lateral movement → AV/EDR disruption → domain-scale Warlock ransomware deployment. EXPLOITATION STATUS: CONFIRMED ACTIVE EXPLOITATION CONFIRMED RANSOMWARE DEPLOYMENT CRITICAL-INFRASTRUCTURE VICTIMS CONFIRMED Forensic triage: Hunt for SharePoint LAYOUTS web shells, Machine Key theft, new privileged accounts, VS Code Tunnel services, BYOVD activity and ransomware/SYSVOL staging. URGENT ACTION: Fully patch on-prem SharePoint. Rotate http://ASP.NET Machine Keys on exposed or suspected systems and restart IIS. Investigate previously vulnerable systems before treating them as clean. SOURCE: https://www.security.com/blog-post/warlock-ransomware-critical-infrastructure EXPLOITATION UPDATE: Symantec observed at least four recent victims: a water utility, telecom operator, regional government body and university across Europe, Africa and Latin America. In one intrusion, an AV/EDR-killing tool reached 40+ hosts and Warlock ransomware was deployed to at least 33 hosts using SYSVOL replication. SUPPORTING SOURCE: https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/ CONFIDENCE: VERY HIGH — direct Symantec/Broadcom incident telemetry. HIGH — Longlegs/Storm-2603 attribution is consistent with prior Microsoft reporting. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #Warlock #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics #Storm2603

    00000116
    226 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2025-49706 Product: Microsoft / SharePoint Summary: VulnCheck reports real-world exploitation activity affecting Microsoft / SharePoint. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 18 Jul 2025 Source: https://vulncheck.com/xdb/7778878554f4 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Microsoft #SharePoint #CVE_2025_49706 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000054
    226 followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    General

    استجابة 401 قد تبدو نهاية الطريق، لكنها أحياناً تخفي مساراً أعمق. مراجعة N Day لثغرة CVE-2025-49706 في SharePoint تكشف كيف يمكن لتفاصيل المصادقة أن تغيّر قراءة المخاطر. A 401 response can look like a dead end, but it may hide the real path. This N Day review of CVE-2025-49706 in SharePoint shows why authentication behavior deserves close attention during vulnerability analysis. https://y4nush.com/posts/the-401-that-fooled-me-n-day-review-of-cve-2025-49706-in-sharepoint/ #SharePoint #CVE202549706 #VulnerabilityResearch

    Post summary

    The article analyzes how authentication nuances affect the risk assessment of SharePoint CVE‑2025‑49706, but it provides no PoC, exploit code, or patch information.

    0000043
    78 followersView on X
  • DailyCVE@dailycve
    General

    🟠 #Microsoft SharePoint Server, Spoofing Vulnerability, #CVE-2025-49706 (Medium) https://dailycve.com/microsoft-sharepoint-server-spoofing-vulnerability-cve-2025-49706-medium/

    Post summary

    The post merely references the existence of CVE‑2025‑49706 for a spoofing flaw in Microsoft SharePoint Server, without providing technical details, PoC, exploitation evidence, or remediation information.

    0000056
    181 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_enterprise_server2016--
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2019--

Explore more