CVE-2026-66805

8.8

Microsoft · SharePoint Server

A deserialization of untrusted data vulnerability in Microsoft SharePoint Server allows an authenticated attacker to execute arbitrary code via a network request.

Executive summary

Multiple versions of Microsoft SharePoint are affected by a high severity deserialization vulnerability that enables remote code execution.

Vulnerability

This is a CWE-502 vulnerability involving the insecure deserialization of untrusted data, which an authenticated attacker can leverage to execute code on the server.

Business impact

With a CVSS score of 8.8, this vulnerability poses a severe risk to the confidentiality, integrity, and availability of SharePoint data. Successful exploitation could result in a full compromise of the SharePoint application tier, potentially impacting all data hosted within the platform.

Remediation

Immediate Action: Install the latest cumulative security updates for your specific version of SharePoint Server as detailed in the vendor advisory.

Proactive Monitoring: Inspect server logs for evidence of unauthorized deserialization attempts or unexpected system calls following the installation of the patches.

Compensating Controls: Implement strict network segmentation and ensure that only authorized users have network access to the SharePoint application servers.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The breadth of affected versions makes this a critical issue for SharePoint administrators. You must verify your current build versions and apply the corresponding security patches immediately to mitigate the risk of remote code execution.

More Microsoft CVEs