Microsoft
Microsoft Sharepoint Server: vulnerabilidades y CVE
Microsoft Sharepoint Server tiene 594 vulnerabilidades publicadas, 151 de ellas en los últimos 12 meses. 15 son críticas y 20 figuran en el catálogo de explotación activa de CISA.
CVE594
Últimos 12 meses151
Críticas15
Explotadas activamente20
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65660 | Alta (8.8) | 2.1% | ⚠ Explotación activa | 11 ago 2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-55040 | Crítica (9.1) | 18% | ⚠ Explotación activa | 14 jul 2026 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-50522 | Crítica (9.8) | 3.0% | ⚠ Explotación activa | 14 jul 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
| CVE-2026-58644 | Crítica (9.8) | 16% | ⚠ Explotación activa | 14 jul 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
| CVE-2026-56164 | Crítica (9.8) | 1.0% | ⚠ Explotación activa | 14 jul 2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-45659 | Alta (8.8) | 2.7% | ⚠ Explotación activa | 22 may 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-32201 | Media (6.5) | 0.98% | ⚠ Explotación activa | 14 abr 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-20963 | Crítica (9.8) | 30% | ⚠ Explotación activa | 13 ene 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49706 | Media (6.5) | 99% | ⚠ Explotación activa | 8 jul 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-49704 | Alta (8.8) | 100% | ⚠ Explotación activa | 8 jul 2025 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-53770 | Crítica (9.8) | 100% | ⚠ Explotación activa | 20 jul 2025 | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.… |
| CVE-2024-38094 | Alta (7.2) | 51% | ⚠ Explotación activa | 9 jul 2024 | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2023-24955 | Alta (7.2) | 85% | ⚠ Explotación activa | 9 may 2023 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2023-29357 | Crítica (9.8) | 100% | ⚠ Explotación activa | 14 jun 2023 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2012-2539 | Alta (7.8) | 53% | ⚠ Explotación activa | 12 dic 2012 | Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service… |
| CVE-2017-11826 | Alta (7.8) | 81% | ⚠ Explotación activa | 13 oct 2017 | Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office… |
| CVE-2014-1761 | Alta (7.8) | 77% | ⚠ Explotación activa | 25 mar 2014 | Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office… |
| CVE-2020-1147 | Alta (7.8) | 94% | ⚠ Explotación activa | 14 jul 2020 | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and… |
| CVE-2015-1641 | Alta (7.8) | 97% | ⚠ Explotación activa | 14 abr 2015 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office… |
| CVE-2019-0604 | Crítica (9.8) | 100% | ⚠ Explotación activa | 5 mar 2019 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69904 | Baja (3.5) | 0.58% | — | 8 sept 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. |
| CVE-2026-69804 | Alta (7.5) | 0.51% | — | 8 sept 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-69724 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-69716 | Alta (8.8) | 0.99% | — | 8 sept 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69690 | Media (5.4) | 0.40% | — | 8 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-69683 | Alta (7.7) | 0.84% | — | 8 sept 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. |
| CVE-2026-69636 | Media (6.5) | 1.00% | — | 8 sept 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. |
| CVE-2026-69615 | Media (4.8) | 0.40% | — | 8 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-69465 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-69464 | Alta (8.8) | 0.91% | — | 8 sept 2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69417 | Media (5.4) | 0.45% | — | 8 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-69409 | Media (6.5) | 1.00% | — | 8 sept 2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. |
| CVE-2026-69402 | Media (5.4) | 0.45% | — | 8 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-69282 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-69273 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-69268 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-70355 | Alta (8.7) | 0.78% | — | 11 ago 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-70326 | Alta (8.8) | 0.78% | — | 11 ago 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-70324 | Alta (8.8) | 0.94% | — | 11 ago 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-70321 | Alta (8.8) | 1.7% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-70306 | Crítica (9.3) | 1.0% | — | 11 ago 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66808 | Alta (8.8) | 2.0% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-66805 | Alta (8.8) | 2.0% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-65665 | Alta (8.8) | 1.7% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-65663 | Alta (8.8) | 2.0% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-65660 | Alta (8.8) | 2.1% | ⚠ Explotación activa | 11 ago 2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-65658 | Alta (8.8) | 2.0% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-64922 | Media (5.4) | 0.58% | — | 11 ago 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-64921 | Alta (8.8) | 0.94% | — | 11 ago 2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-64916 | Media (5.4) | 0.58% | — | 11 ago 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |