CVE-2026-65658

8.8

Microsoft · SharePoint

An insecure deserialization vulnerability in Microsoft SharePoint allows an authenticated attacker to execute arbitrary code over the network.

Executive summary

This high-severity deserialization vulnerability affects multiple versions of Microsoft SharePoint and allows an authenticated attacker to execute arbitrary code.

Vulnerability

The software fails to properly sanitize untrusted data during deserialization, which can be leveraged by an authenticated attacker to achieve remote code execution. The attack vector requires low privileges to trigger the flaw over the network.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain complete control over the affected SharePoint server. This level of access leads to full data compromise, unauthorized modification of sensitive corporate documents, and potential lateral movement within the internal network, justifying the high CVSS score of 8.8.

Remediation

Immediate Action: Apply the security updates provided by Microsoft in the official update guide to the specified patched version levels.

Proactive Monitoring: Review SharePoint audit logs for unusual process execution or unauthorized modifications to sensitive site configurations.

Compensating Controls: Ensure that the SharePoint server is isolated from untrusted networks and utilize a Web Application Firewall to monitor for suspicious serialized payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution and the high severity of this flaw, organizations must prioritize patching all affected SharePoint instances. Testing and deploying the vendor-supplied updates is the only definitive method to remediate this vulnerability.

More Microsoft CVEs