News
Microsoft servers are at risk due to a serious vulnerability
It is a vulnerability that could well endanger thousands of companies

- July 28, 2025
- Updated: July 28, 2025 at 10:50 AM

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about two critical vulnerabilities in Microsoft SharePoint, designated as CVE-2025-49704 and CVE-2025-49706. Both vulnerabilities are being actively exploited worldwide, posing a significant risk to organizations operating on-premises SharePoint servers.
A vulnerability that can be critical
The first vulnerability, CVE-2025-49704, is a serious code injection flaw that allows authorized attackers to execute arbitrary code through a network connection, which could result in full control over the compromised server. This vulnerability is classified as CWE-94, referring to Improper Control of Code Generation, and may result in the exposure of sensitive data and a potential information exfiltration.
On the other hand, CVE-2025-49706 is a vulnerability of incorrect authentication that facilitates spoofing attacks, allowing attackers to bypass authentication controls and gain unauthorized access to critical information. This flaw is classified under CWE-287, and its successful exploitation allows attackers to modify data and compromise the integrity of SharePoint environments.
When both vulnerabilities are combined, they create a powerful attack vector. Attackers often use CVE-2025-49706 to bypass authentication and then exploit CVE-2025-49704 to inject malicious code. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of 24 hours, highlighting the urgency and severity of the situation.
Likewise, CISA has recommended that organizations take immediate action, especially those using versions of SharePoint that are no longer supported. For supported versions, it is urged to apply the latest security patches and to follow the mitigation guidelines recommended by Microsoft.
Latest from Softonic
- If you want to complete Super Meat Boy without dying a single time, it will take you between 700 and 800 hours
- The developers of Expedition 33 know what not to do to make their next game a success
- STALKER 2 will continue to receive updates throughout 2026
- The creator of Counter-Strike left Valve because he wanted to do something more ambitious than just improving the game's graphics
You may also like
NewsIf you want to complete Super Meat Boy without dying a single time, it will take you between 700 and 800 hours
Read more
NewsThe developers of Expedition 33 know what not to do to make their next game a success
Read more
NewsSTALKER 2 will continue to receive updates throughout 2026
Read more
NewsThe creator of Counter-Strike left Valve because he wanted to do something more ambitious than just improving the game's graphics
Read more
NewsStranger Things has had a great ending, but one of its characters has been left out from the rest
Read more
NewsAvatar: Fire and Ash surpasses one billion dollars, but two movies surpass it at the box office in 2025
Read more