Microsoft Fixes Power Pages Critical Flaw Exploited in Active Attacks

Red | Vulnerability Report
Download PDF

Microsoft has patched a critical vulnerability, CVE-2025-24989, in Power Pages, which was actively exploited in attacks. This flaw stems from improper access controls, allowing attackers to escalate privileges over a network and bypass user registration restrictions. Since hackers have already been exploiting this vulnerability, organizations using Power Pages should apply the fix immediately to prevent unauthorized access.