CVE-2025-49706Medium· 6.5▾ Midnight⚠ Exploited in the wildPoC availableImproper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 35.8 · likelihood 19.8 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jul 23, 2025
Last analysed / modified upstream
100%
1 GitHub repo · Metasploit ×1 · Nuclei ×1
Added to the CISA catalog on Jul 22, 2025. Federal remediation due Jul 23, 2025. View catalog ↗
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
sharepoint_enterprise_server = 2016sharepoint_server < 16.0.18526.20424sharepoint_server = 2019Upgrade past the affected range:
sharepoint_server 16.0.18526.20424Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-49039High· 8.8Windows Task Scheduler Elevation of Privilege Vulnerability
CVE-2023-49105Critical· 9.8An issue was discovered in ownCloud owncloud/core before 10.13.1
CVE-2022-40684Critical· 9.8An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 …
CVE-2023-35078Critical· 9.8An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.