Sharepoint Server CVE patch breaks BCS .NET connections
Over the past weekend, SharePoint Server was back in the news! 0-Day vulnerabilty was exploited, some servers were compromised, and Microsoft was scrambling to get the patches out. It was CVE-2025-53770 and a few related vulnerabilities that stirred up the quiet world of SharePoint on-prem. While it was refreshing to see that SharePoint Server is very much alive despite the focus on cloud-based SharePoint Online, the entire affair has underscored that Microsoft doesn’t spend resources on SharePoint Server maintenance as much as before.
As expected, the SharePoint SE patch was released first, followed by patches for SharePoint 2019 and 2016. However, it soon became apparent that the patch caused issues with UI elements on modern pages in SharePoint 2019. It took Microsoft a few more hours to release additional patch for SP2019, and then, finally, SP2016 patches were released too. I don’t want to get into more details (get them on Microsoft’s customer guidance page), because this post is about something that not been clearly documented by Microsoft: the impact on Business Connectivity Services (BCS) with .NET connectors.