CVE-2025-49706
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Published:Jul 8, 2025
Last Modified:Feb 26, 2026
EPS:Jul 8, 2025
EPSS Score:0.65002
CVSS Score:6.5
CISA Notification
Description
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Required Action:
Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Notes:
No extra notes provided.
Due Date
Jul 23, 2025
415 days ago
Alert Date
Jul 22, 2025
416 days ago
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Sharepoint Enterprise Server
Microsoft
Sharepoint Enterprise Server
Vendor
Microsoft
Product
Sharepoint Server
Microsoft
Sharepoint Server
Vendor
Microsoft
Product
Sharepoint Server 2016
Microsoft
Sharepoint Server 2016
Vendor
Microsoft
Product
Sharepoint Server 2019
Microsoft
Sharepoint Server 2019
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
