Microsoft MSRC:
| Revision | Change | Date |
|---|---|---|
| 1.0 | Information published | 07/19/25 |
| 2.0 | Clarified affected SharePoint product in summary | 07/20/25 |
| Added fix availability guidance | ||
Provided additional protections guidance regarding:
| ||
| Updated Microsoft Defender detections and protections section: | ||
| Documented additional MDE alerts | ||
| Mapping exposure via Microsoft Defender Vulnerability Management | ||
| Documented CVE-2025-53771 | ||
| 3.0 | Published SharePoint 2019 security update, included links to CVEs and published security updates |
Summary
Microsoft is aware of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July Security Update.These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted.
Microsoft has released security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 against the risks posed by CVE-2025-53770, and CVE-2025-53771. Customers should apply these updates immediately to ensure they’re protected.
| Product | Security Update link |
|---|---|
| Microsoft SharePoint Server Subscription Edition | Download Security Update for Microsoft SharePoint Server Subscription Edition (KB5002768) from Official Microsoft Download Center |
| Microsoft SharePoint Server 2019 | Download Security Update for Microsoft SharePoint Server Subscription Edition (KB5002754) from Official Microsoft Download Center |
| Microsoft SharePoint Server 2016 | Not available yet |
We are working on security updates for supported versions of SharePoint 2019 and SharePoint 2016. Please check this blog for updates.
To mitigate potential attacks customers should:
- Use supported versions of on-premises SharePoint Server
- Apply the latest security updates, including the July 2025 Security Update
- Ensure the Antimalware Scan Interface (AMSI) is turned on and configured correctly, with an appropriate antivirus solution such as Defender Antivirus
- Deploy Microsoft Defender for Endpoint protection, or equivalent threat solutions
- Rotate SharePoint Server ASP.NET machine keys
Read more:






