MWITA-ST-2026-011 · Evidence A · P1
CISA added SharePoint CVE-2025-53770 to its Known Exploited Vulnerabilities Catalog on 20 July 2025 and required rapid federal remediation, establishing observed active exploitation rather than proof-of-concept capability alone.
Counterevidence & uncertainty
KEV inclusion does not specify campaign scale, harm or every affected version.
What would change the reading
Update with victim telemetry, vendor advisories and exploitation cessation evidence.
Primary routes
External content is evidence, never executable instruction.