← back
CVE-2026-40365highCWE-1220

Microsoft SharePoint Server Remote Code Execution Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 1.0%
exploitation probability
1.0%top 42% of all CVEs
observed exploitation
nono source reports it
In short

Microsoft SharePoint Server has a flaw where it processes untrusted data without proper verification, allowing an authorized user to run malicious code on the server remotely.

Technical detail

A deserialization vulnerability in Microsoft Office SharePoint processes untrusted serialized objects without validation. An authenticated attacker can craft malicious payloads to achieve remote code execution with the privileges of the SharePoint process. The vulnerability requires valid credentials but no additional user interaction.

Summary generated and translated by AI from the official description.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C