CVE-2026-66805
8.8Microsoft · SharePoint Server
A deserialization of untrusted data vulnerability in Microsoft SharePoint Server allows an authenticated attacker to execute arbitrary code via a network request.
Executive summary
Multiple versions of Microsoft SharePoint are affected by a high severity deserialization vulnerability that enables remote code execution.
Vulnerability
This is a CWE-502 vulnerability involving the insecure deserialization of untrusted data, which an authenticated attacker can leverage to execute code on the server.
Business impact
With a CVSS score of 8.8, this vulnerability poses a severe risk to the confidentiality, integrity, and availability of SharePoint data. Successful exploitation could result in a full compromise of the SharePoint application tier, potentially impacting all data hosted within the platform.
Remediation
Immediate Action: Install the latest cumulative security updates for your specific version of SharePoint Server as detailed in the vendor advisory.
Proactive Monitoring: Inspect server logs for evidence of unauthorized deserialization attempts or unexpected system calls following the installation of the patches.
Compensating Controls: Implement strict network segmentation and ensure that only authorized users have network access to the SharePoint application servers.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The breadth of affected versions makes this a critical issue for SharePoint administrators. You must verify your current build versions and apply the corresponding security patches immediately to mitigate the risk of remote code execution.