Sharepoint Server

by Microsoft

Take action — actively targeted

Sharepoint Server is actively targeted by attackers. A significant proportion of its known vulnerabilities are being exploited.

What to do
  1. Apply all available updates immediately
  2. Review your exposure — is this internet-facing?
  3. Monitor vendor advisories for this product

What Attackers Target

Vulnerabilities with high exploit probability 36.9%
Confirmed actively exploited (CISA) 3.3%
Public exploit code available 0.3%
Based on 396 known vulnerabilities. Percentages show the proportion that are actively dangerous — a low percentage means most vulnerabilities in this product are not being exploited.

Most Dangerous Vulnerabilities

CVE CVSS Exploit Probability Confirmed
CVE-2019-0604 9.8 94.4% Yes
CVE-2023-29357 9.8 94.4% Yes
CVE-2015-1641 7.8 93.6% Yes
CVE-2020-1147 7.8 93.4% Yes
CVE-2014-1761 7.8 92.6% Yes
CVE-2023-24955 7.2 91.6% Yes
CVE-2023-21716 9.8 91.4%
CVE-2017-11826 7.8 90.8% Yes
CVE-2025-53770 9.8 88.7% Yes
CVE-2012-2539 7.8 84.4% Yes
CVE-2020-16952 8.6 75.1%
CVE-2025-49706 6.5 71.6% Yes
CVE-2013-0006 8.8 68.3%
CVE-2024-38094 7.2 64.3% Yes
CVE-2024-43464 7.2 63.9%
CVE-2025-49704 8.8 59.6% Yes
CVE-2016-3282 7.8 54.6%
CVE-2024-30043 6.5 54.1%
CVE-2020-1181 8.8 52.6%
CVE-2016-0134 7.8 48.5%
53
/ 100
high-risk
Active Threat 50/50 · Critical
Exploit Availability 3/50 · Minimal

Score uses Wilson score intervals to account for sample size. Products with few CVEs are scored conservatively.