Product overview
SharePoint Server is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Networked or application service delivery
- Administrative and operational interfaces
- Versioned maintenance and security updates
Typical use
Used to provide application, infrastructure or operational services to other systems and users.
Deployment
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | Microsoft SharePoint Server |
|---|
| Release | 2010 |
|---|
| End of Fixed Lifecycle Policy | 14 April 2021 |
|---|
| Date precision | Day |
|---|
Known exploited vulnerabilities
Catalogue updated 11 Sep 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Microsoft · SharePoint ServerRansomware use: Unknown
CISA entry ↗Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Microsoft · SharePoint ServerRansomware use: Known
CISA entry ↗Microsoft SharePoint Server Improper Input Validation Vulnerability
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Microsoft · SharePoint ServerRansomware use: Unknown
CISA entry ↗Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
Microsoft · SharePointRansomware use: Known
CISA entry ↗Microsoft SharePoint Server Code Injection Vulnerability
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
Microsoft · SharePoint ServerRansomware use: Known
CISA entry ↗Microsoft SharePoint Server Privilege Escalation Vulnerability
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.
Microsoft · SharePoint ServerRansomware use: Known
CISA entry ↗Showing the 6 most recently added of 7 product-family matches.
Package vulnerability advisories
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Source evidence
PRIMARYReady
Microsoft lifecycle discovery
{"display_products": ["Office"], "end": "2021-04-14T06:59:59.999Z", "last_modified": "2022-10-25T00:00:00Z", "locale": "en-us", "products": ["office"], "start": "2010-07-15T08:00:00Z", "summary": "Microsoft SharePoint Server 2010 follows the Fixed Lifecycle Policy.", "title": "Microsoft SharePoint Server 2010", "url": "/lifecycle/products/microsoft-sharepoint-server-2010"}
Official vendor lifecycle or product-change property. Extracted records require human review.
First collected 25 Aug 2026 · Last collected 12 Sep 2026 · Review state accepted
Open official vendor source ↗