cbcvebase.

Microsoft Sharepoint Enterprise Server 2016 vulnerabilities

335 known vulnerabilities affecting microsoft/microsoft_sharepoint_enterprise_server_2016.

Total CVEs
335
CISA KEV
12
actively exploited
Public exploits
18
Exploited in wild
21
Severity breakdown
CRITICAL11HIGH188MEDIUM129LOW7

Vulnerabilities

Page 1 of 17
CVE-2025-53770P1CRITICALCVSS 9.8KEVPoCRansomware≥ 16.0.0, < 16.0.5513.10012025-07-20
CVE-2025-53770 [CRITICAL] CWE-502 CVE-2025-53770: Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that t
nvd
CVE-2025-49704P1HIGHCVSS 8.8KEVPoCRansomware≥ 16.0.0, < 16.0.5508.10002025-07-08
CVE-2025-49704 [HIGH] CWE-94 CVE-2025-49704: Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an a Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50522P1CRITICALCVSS 9.8KEVPoC≥ 16.0.0, < 16.0.5561.10012026-07-14
CVE-2026-50522 [CRITICAL] CWE-502 CVE-2026-50522: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45659P1HIGHCVSS 8.8KEVPoCRansomware≥ 16.0.0, < 16.0.5552.10022026-05-22
CVE-2026-45659 [HIGH] CWE-502 CVE-2026-45659: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
cvelistv5nvd
CVE-2025-49706P1MEDIUMCVSS 6.5KEVPoCRansomware≥ 16.0.0, < 16.0.5508.10002025-07-08
CVE-2025-49706 [MEDIUM] CWE-287 CVE-2025-49706: Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform sp Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-55040P1CRITICALCVSS 9.1KEVPoC≥ 16.0.0, < 16.0.5561.10012026-07-14
CVE-2026-55040 [CRITICAL] CWE-1390 CVE-2026-55040: Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a secur Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-24955P1HIGHCVSS 7.2KEVPoCRansomware≥ 16.0.0, < 16.0.5395.10002023-05-09
CVE-2023-24955 [HIGH] CWE-94 CVE-2023-24955: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-58644P1CRITICALCVSS 9.8KEVPoC≥ 16.0.0, < 16.0.5556.10052026-07-14
CVE-2026-58644 [CRITICAL] CWE-502 CVE-2026-58644: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-32201P1MEDIUMCVSS 6.5KEVPoC≥ 16.0.0, < 16.0.5548.10032026-04-14
CVE-2026-32201 [MEDIUM] CWE-20 CVE-2026-32201: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-56164P1CRITICALCVSS 9.8KEV≥ 16.0.0, < 16.0.5561.10012026-07-14
CVE-2026-56164 [CRITICAL] CWE-306 CVE-2026-56164: Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized a Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-20963P1CRITICALCVSS 9.8KEV≥ 16.0.0, < 16.0.5535.10012026-01-13
CVE-2026-20963 [CRITICAL] CWE-502 CVE-2026-20963: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-38094P1HIGHCVSS 7.2KEVRansomware≥ 16.0.0, < 16.0.5456.10002024-07-09
CVE-2024-38094 [HIGH] CWE-502 CVE-2024-38094: Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2023-21716P1CRITICALCVSS 9.8ExploitedPoC≥ 16.0.0, < 16.0.5383.10002023-02-14
CVE-2023-21716 [CRITICAL] CWE-190 CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2025-53771P1MEDIUMCVSS 6.5ExploitedPoCRansomware≥ 16.0.0, < 16.0.5513.10012025-07-20
CVE-2025-53771 [MEDIUM] CWE-287 CVE-2025-53771: Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform sp Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2023-21742P1HIGHCVSS 8.8ExploitedPoC≥ 16.0.0, < 16.0.5378.10002023-01-10
CVE-2023-21742 [HIGH] CWE-284 CVE-2023-21742: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-63520P1HIGHCVSS 8.1ExploitedPoC≥ 16.0.0, < 16.0.5565.10012026-08-11
CVE-2026-63520 [HIGH] CWE-20 CVE-2026-63520: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-38023P2HIGHCVSS 7.2Exploited≥ 16.0.0, < 16.0.5456.10002024-07-09
CVE-2024-38023 [HIGH] CWE-502 CVE-2024-38023: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2024-38024P2HIGHCVSS 7.2Exploited≥ 16.0.0, < 16.0.5456.10002024-07-09
CVE-2024-38024 [HIGH] CWE-502 CVE-2024-38024: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-22005P1HIGHCVSS 8.8Exploited≥ 16.0.0, < 16.0.5278.10002022-02-09
CVE-2022-22005 [HIGH] CWE-502 CVE-2022-22005: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-27076P1HIGHCVSS 8.8Exploited≥ 16.0.0, < 16.0.5134.10002021-03-11
CVE-2021-27076 [HIGH] CVE-2021-27076: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
1 / 17Next →
Microsoft Sharepoint Enterprise Server 2016 vulnerabilities | cvebase