known ransomware use

Microsoft SharePoint Remote Code Execution Vulnerability

Added to KEV
2021-11-03
Federal due date
2022-05-03
Vendor
Microsoft
Product
SharePoint
EPSS
100.0th percentile (score 0.944, as of 2026-06-08)
NVD CVSS v3.1
Ransomware use
Known
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2019-0604

CISA short description

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

Required action

Apply updates per vendor instructions.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.