KB5002744: SharePoint Framework (SPFx)
Description of the security update for SharePoint Enterprise Server 2016: July 8, 2025 (KB5002744)
Summary
This security update resolves a Microsoft SharePoint remote code execution vulnerability, Microsoft SharePoint Server spoofing vulnerability, and Microsoft Word remote code execution vulnerability. To learn more about the vulnerabilities, see the following security advisories:
- Microsoft Common Vulnerabilities and Exposures CVE-2025-49701
- Microsoft Common Vulnerabilities and Exposures CVE-2025-49703
- Microsoft Common Vulnerabilities and Exposures CVE-2025-49704
- Microsoft Common Vulnerabilities and Exposures CVE-2025-49706
This public update delivers Feature Pack 2 for SharePoint Server 2016. Feature Pack 2 contains the following feature:
SharePoint Framework (SPFx)
This public update also delivers all the features that were included in Feature Pack 1 for SharePoint Server 2016, including:
- Administrative Actions Logging
- MinRole enhancements
- SharePoint Custom Tiles
- Hybrid Taxonomy
- OneDrive API for SharePoint on-premises
- OneDrive for Business modern user experience (available to Software Assurance customers)