Microsoft SharePoint Server

Our sources currently list 558 known vulnerabilities affecting Microsoft SharePoint Server. 44 are rated critical severity. 18 of 558 are actively exploited according to CISA, the most recent added 16 July 2026.

Last updated: 22 July 2026, 20:31 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in Microsoft SharePoint Server, highest risk first.Showing the 50 highest-risk of 558 total.
CVESeverityExploitationPublishedSummary
CVE-2025-53770Critical (9.8)Actively exploited · ransomwareDeserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for …
CVE-2019-0604Critical (9.8)Actively exploited · ransomwareA remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote …
CVE-2025-49704High (8.8)Actively exploited · ransomwareImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-49706Medium (6.5)Actively exploited · ransomwareImproper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2023-29357Critical (9.8)Actively exploited · ransomwareMicrosoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2015-1641High (7.8)Actively exploitedMicrosoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint S…
CVE-2020-1147High (7.8)Actively exploitedA remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.…
CVE-2023-24955High (7.2)Actively exploited · ransomwareMicrosoft SharePoint Server Remote Code Execution Vulnerability
CVE-2012-1889High (8.8)Actively exploitedMicrosoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (me…
CVE-2017-11826High (7.8)Actively exploitedMicrosoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 201…
CVE-2014-1761High (7.8)Actively exploitedMicrosoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv…
CVE-2012-2539High (7.8)Actively exploitedMicrosoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrar…
CVE-2024-38094High (7.2)Actively exploited · ransomwareMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-20963Critical (9.8)Actively exploitedDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-32201Medium (6.5)Actively exploitedImproper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-56164Medium (5.3)Actively exploitedMissing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-45659High (8.8)Actively exploitedDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-58644Critical (9.8)Actively exploitedDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2025-53771Medium (6.5)Elevated likelihood (100%)Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2010-3964High (7.5)Elevated likelihood (94%)Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Serv…
CVE-2024-30044High (7.2)Elevated likelihood (84%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2023-21716Critical (9.8)Elevated likelihood (82%)Microsoft Word Remote Code Execution Vulnerability
CVE-2022-44690High (8.8)Elevated likelihood (82%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-38053High (8.8)Elevated likelihood (76%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2013-0081Medium (5.0)Elevated likelihood (75%)Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers t…
CVE-2020-16952High (8.6)Elevated likelihood (71%)<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully e…
CVE-2020-1181High (8.8)Elevated likelihood (69%)A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Ser…
CVE-2023-24950Medium (6.5)Elevated likelihood (67%)Microsoft SharePoint Server Spoofing Vulnerability
CVE-2013-3180Medium (4.3)Elevated likelihood (66%)Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST …
CVE-2023-21742High (8.8)Elevated likelihood (56%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-30043Medium (6.5)Elevated likelihood (55%)Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2024-38023High (7.2)Elevated likelihood (53%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-35823High (8.8)Elevated likelihood (53%)Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2024-38018High (8.8)Elevated likelihood (51%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-28474High (8.8)Elevated likelihood (51%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-37961High (8.8)Elevated likelihood (50%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-40487High (8.1)Elevated likelihood (46%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-38024High (7.2)Elevated likelihood (45%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2023-33157High (8.8)Elevated likelihood (41%)Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2018-8284High (8.1)Elevated likelihood (40%)A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affe…
CVE-2011-1892Medium (4.0)Elevated likelihood (38%)Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP…
CVE-2007-2581Medium (4.3)Elevated likelihood (36%)Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to…
CVE-2024-43464High (7.2)Elevated likelihood (36%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2008-3006Critical (9.3)Elevated likelihood (36%)Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Office Compatibility Pack 2007 Gold …
CVE-2025-21400High (8.0)Elevated likelihood (34%)Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2008-4019Critical (9.3)Elevated likelihood (34%)Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Comp…
CVE-2013-0085High (7.8)Elevated likelihood (34%)Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage)…
CVE-2015-6038Critical (9.3)Elevated likelihood (33%)Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, and Ex…
CVE-2013-0007Critical (9.3)Elevated likelihood (32%)Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "…
CVE-2020-0932High (8.8)Elevated likelihood (31%)A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote …

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

18 of these are being actively exploited right now.

Our Newcastle team can audit your Microsoft estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.