A deep dive into CVE-2025-49706 — the SharePoint spoofing flaw now exploited in the wild for stealthy web shell deployment and privilege escalation.
-
Updated
Jul 20, 2025
A deep dive into CVE-2025-49706 — the SharePoint spoofing flaw now exploited in the wild for stealthy web shell deployment and privilege escalation.
A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706.
Add a description, image, and links to the cve-2025-49706 topic page so that developers can more easily learn about it.
To associate your repository with the cve-2025-49706 topic, visit your repo's landing page and select "manage topics."