KEVIntel
6.5
CVSS
Medium

CVE-2025-49706

PUBLISHED

Microsoft SharePoint Server Spoofing Vulnerability

1 day faster than CISA KEV

Exploited in the wild Used in malware PoC available Remote Low complexity No user interaction
Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Published
Jul 08, 2025
EPSS
73.8% · 99% pctl

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

cisa malware nuclei_scanner microsoft

Weaknesses (CWE)

CVSS Scores

CVSS v3.1 6.5 Medium

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Exploitation Status

Exploited in the wild

Recorded 2026-06-01 10:37:23 UTC · CVE

Used in malware

Recorded 2026-06-02 14:06:59 UTC · CVE

Proof of concept available

Recorded 2026-06-12 14:21:08 UTC · Nuclei Templates

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2026-06-01 10:37 UTC
CISA 2026-06-02 14:06 UTC

Scanner Integrations

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

CVE-2025-49706

nuclei · Created Unknown

Timeline

  • Proof of Concept Exploit Available

  • Exploit Used in Malware

  • KEV confirmed by CISA

  • Detected by Nuclei

  • Added to KEVIntel

  • CVE Published to Public

  • CVE ID Reserved