Update: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) released an updated alert to reflect newly released information from Microsoft, and to correct the actively exploited Common Vulnerabilities and Exposures (CVEs), which have been confirmed as CVE-2025-49706 , a network spoofing vulnerability, and CVE-2025-49704, a remote code execution (RCE) vulnerability. CISA is aware of [...]

