Skip to content
COOEY

FAIL › dossier

SharePoint

PRODUCT

· dossier confidence 60%

Microsoft's SharePoint platform suffers from a chronic vulnerability to critical remote code execution flaws, which are actively exploited by ransomware and state-sponsored actors. Despite emergency patches, exploitation persists, indicating incomplete fixes and a need for layered enterprise defenses.

PROFILE
CategoryEnterprise SoftwareWhat they doMicrosoft develops and supports software, services, devices, and solutions worldwide, including the SharePoint platform for collaboration and document management.Founded1975Ownershippublic Websitehttps://www.microsoft.com ↗
SECURITY POSTURE

Microsoft's security posture is severely compromised by a persistent pattern of critical remote code execution (RCE) vulnerabilities in SharePoint, frequently exploited by ransomware and state-sponsored actors even after patches are released.

Notable failures
  • CVE-2019-0604: Critical RCE via untrusted markup
  • CVE-2025-53770: Actively exploited 'ToolShell' RCE
  • CVE-2025-49704: Critical RCE exploited by ransomware
Patterns: Repeated critical RCE vulnerabilities in SharePoint; Active exploitation of unpatched or post-patched vulnerabilities; Ransomware and state-sponsored actor targeting of SharePoint
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2019-0604 critical Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.
2026-03-18 CVE-2026-20963 high Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited.
2025-07-22 CVE-2025-49704 critical Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors.
2025-07-20 CVE-2025-53770 critical Microsoft SharePoint on-premises suffered a deserialization of untrusted data vulnerability allowing remote code execution, actively exploited in the wild and linked to ransomware.
2024-10-22 CVE-2024-38094 critical Microsoft SharePoint's deserialization flaw allowed remote code execution and was actively exploited by ransomware actors.
2025-07-22 CVE-2025-49706 critical Microsoft SharePoint's improper authentication flaw allowed attackers to spoof network requests, view sensitive data, and modify information.
2026-07-22 CVE-2026-50522 high Microsoft SharePoint RCE due to untrusted data deserialization
2026-07-16 CVE-2026-58644 high Microsoft SharePoint RCE due to untrusted data deserialization
2026-08-18 CVE-2026-55040 high Microsoft SharePoint's weak authentication flaw lets attackers bypass security controls over a network.
Open questions: Specific patch timelines for CVE-2025-49704 and CVE-2025-53770 · Current status of Microsoft's deserialization mitigation framework
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:18:20.052016+00:00