CVE-2026-70321
8.8Microsoft · SharePoint
A deserialization of untrusted data vulnerability in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to execute code over a network.
Executive summary
This high-severity vulnerability in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to execute arbitrary code, potentially leading to a full system compromise.
Vulnerability
The vulnerability involves improper deserialization of untrusted data (CWE-502). It is exploitable by an authenticated attacker over a network, requiring low privileges to execute code on the host server.
Business impact
A successful exploit grants the attacker the ability to execute commands with the privileges of the SharePoint service, which often holds high-level access. With a CVSS score of 8.8, this flaw represents a significant risk to organizational data security and system stability, potentially allowing for lateral movement or data theft.
Remediation
Immediate Action: Update the affected Microsoft SharePoint Server Subscription Edition instance to version 16.0.19725.20522 or higher as specified by the vendor.
Proactive Monitoring: Monitor server-side logs for signs of unauthorized code execution or unusual behavior in SharePoint service accounts.
Compensating Controls: Utilize endpoint detection and response (EDR) solutions to identify and block unauthorized child processes spawned by the SharePoint web service.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this deserialization vulnerability necessitates immediate attention. IT administrators should verify their SharePoint server versions and apply the necessary security patches provided by Microsoft to eliminate the risk of remote code execution.