ENISA EU KEV catalog membership for CVE-2025-53770
ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.
Vulnerability threat dossier
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
VTP analyst assessment
Critical deserialization vulnerability in on-premises SharePoint Server permitting unauthenticated network code execution. Supplied KEV context and independent ENISA EU KEV evidence establish known global exploitation.
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.
The supplied source does not describe exploitation volume, techniques, or affected organizations.
Local SharePoint exposure, mitigation status, and compromise are unknown without first-party telemetry.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
On-premises SharePoint 2016, 2019, or Subscription Edition instances matching affected versions.
VTP deterministic assessment
CISA KEV lists this vulnerability as known to be exploited globally.
EPSS is 1.00; this is predictive context, not exploitation evidence.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Material change ledger
Claim provenance
1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Event history
ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.
CISA lists global known exploitation. This is not a VTP sensor observation.
Original publications
ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.
Technical vulnerability data
Raw observations
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.