The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two Microsoft SharePoint vulnerabilities, CVE-2025-49704 and CVE-2025-49706, to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation as of July 22, 2025. Federal Civilian Executive Branch (FCEB) agencies must remediate these vulnerabilities by July 23, 2025.