CVE-2026-65665

8.8

Microsoft · SharePoint Server

A deserialization of untrusted data vulnerability in Microsoft SharePoint Server allows an authenticated attacker to execute arbitrary code over a network.

Executive summary

Microsoft SharePoint Server contains a high severity remote code execution vulnerability that requires low privileges to exploit.

Vulnerability

The software is susceptible to CWE-502, Deserialization of Untrusted Data, which allows an authenticated attacker with low privileges to trigger remote code execution.

Business impact

Successful exploitation allows an attacker to gain unauthorized code execution on the underlying server. Given the CVSS score of 8.8, this vulnerability poses a significant risk of full system compromise, data theft, and potential lateral movement within the enterprise network.

Remediation

Immediate Action: Apply the latest security updates provided by Microsoft in the official security update guide for this CVE.

Proactive Monitoring: Monitor server logs for suspicious process creation or unusual network traffic originating from service accounts.

Compensating Controls: Ensure that SharePoint instances are isolated within secure network segments and restrict access to authorized users only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize patching affected SharePoint environments immediately. Given the high impact of remote code execution, rapid deployment of the vendor provided updates is necessary to secure the infrastructure against potential exploitation.

More Microsoft CVEs