FAIL › dossier
SharePoint
PRODUCT· dossier confidence 60%
Microsoft's SharePoint platform suffers from a chronic vulnerability to critical remote code execution flaws, which are actively exploited by ransomware and state-sponsored actors. Despite emergency patches, exploitation persists, indicating incomplete fixes and a need for layered enterprise defenses.
PROFILE
CategoryEnterprise SoftwareWhat they doMicrosoft develops and supports software, services, devices, and solutions worldwide, including the SharePoint platform for collaboration and document management.Founded1975Ownershippublic
Websitehttps://www.microsoft.com ↗
SECURITY POSTURE
Microsoft's security posture is severely compromised by a persistent pattern of critical remote code execution (RCE) vulnerabilities in SharePoint, frequently exploited by ransomware and state-sponsored actors even after patches are released.
Notable failures
- CVE-2019-0604: Critical RCE via untrusted markup
- CVE-2025-53770: Actively exploited 'ToolShell' RCE
- CVE-2025-49704: Critical RCE exploited by ransomware
Patterns: Repeated critical RCE vulnerabilities in SharePoint; Active exploitation of unpatched or post-patched vulnerabilities; Ransomware and state-sponsored actor targeting of SharePoint
FAILURE HISTORY · 9
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2019-0604 | critical | Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity. |
| 2026-03-18 | CVE-2026-20963 | high | Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited. |
| 2025-07-22 | CVE-2025-49704 | critical | Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors. |
| 2025-07-20 | CVE-2025-53770 | critical | Microsoft SharePoint on-premises suffered a deserialization of untrusted data vulnerability allowing remote code execution, actively exploited in the wild and linked to ransomware. |
| 2024-10-22 | CVE-2024-38094 | critical | Microsoft SharePoint's deserialization flaw allowed remote code execution and was actively exploited by ransomware actors. |
| 2025-07-22 | CVE-2025-49706 | critical | Microsoft SharePoint's improper authentication flaw allowed attackers to spoof network requests, view sensitive data, and modify information. |
| 2026-07-22 | CVE-2026-50522 | high | Microsoft SharePoint RCE due to untrusted data deserialization |
| 2026-07-16 | CVE-2026-58644 | high | Microsoft SharePoint RCE due to untrusted data deserialization |
| 2026-08-18 | CVE-2026-55040 | high | Microsoft SharePoint's weak authentication flaw lets attackers bypass security controls over a network. |
DOSSIER SOURCES
- Microsoft (MSFT) Company Profile & Description - Stock Analysis · stockanalysis.com
- History of Microsoft - Wikipedia · en.wikipedia.org
- Microsoft (MSFT) Company Profile, History, Products & Services · www.financecharts.com
- Post-Patch 'ToolShell' Exploit: CVE-2025-53770 Abused in Microsoft ... · dailysecurityreview.com
- Microsoft Patch Tuesday July 2026 Zero-Days: Patch CVE-2026-56155 · www.decryptiondigest.com
- SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 ... · www.tenable.com
Open questions: Specific patch timelines for CVE-2025-49704 and CVE-2025-53770 · Current status of Microsoft's deserialization mitigation framework
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:18:20.052016+00:00