Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Microsoft
PRODUCT: Office SharePoint
AFFECTED_VERSIONS: SharePoint Enterprise Server 2016 (16.0.0 up to 16.0.5552.1002), SharePoint Server 2019 (16.0.0 up to 16.0.10417.20128), SharePoint Server Subscription Edition (16.0.0 up to 16.0.19725.20280)
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A deserialization vulnerability in Microsoft Office SharePoint allows an authenticated attacker to achieve remote code execution over a network.
Executive Summary:
A critical deserialization vulnerability in Microsoft Office SharePoint allows an authenticated attacker to execute arbitrary code, posing a severe risk of full system compromise.
Vulnerability Details
CVE-ID: CVE-2026-35439
Affected Software: Microsoft Office SharePoint
Affected Versions: SharePoint Enterprise Server 2016 (<16.0.5552.1002), SharePoint Server 2019 (<16.0.10417.20128), and SharePoint Server Subscription Edition (<16.0.19725.20280).
Vulnerability: The vulnerability stems from the deserialization of untrusted data (CWE-502). An authenticated attacker can leverage this flaw to execute code over the network, effectively bypassing standard security controls.
Business Impact
With a CVSS score of 8.8, this vulnerability is highly severe. Successful exploitation allows an attacker with low-level access to gain total control over the SharePoint server, facilitating lateral movement, data theft, and potential ransomware deployment within the corporate network.
Remediation Plan
Immediate Action: Apply the relevant security updates provided by Microsoft in the MSRC update guide for CVE-2026-35439.
Proactive Monitoring: Monitor SharePoint server logs for suspicious process spawning or anomalous network traffic originating from the SharePoint application pool identity.
Compensating Controls: Ensure that SharePoint instances are not exposed directly to the internet and enforce strict network segmentation to limit the impact of a potential compromise.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of May 14, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. However, deserialization flaws are notoriously dangerous and often highly sought after by threat actors for weaponization.
Analyst Recommendation
Given the high CVSS score and the critical nature of SharePoint in enterprise environments, patching this vulnerability must be treated as a high-priority task. Administrators should verify their SharePoint versions against the affected ranges and apply the vendor patches immediately.