Executive brief
Microsoft SharePoint, a widely used platform for document management and team collaboration, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to remotely take control of the server over the network. Successful exploitation could lead to the theft of sensitive corporate data, complete service disruption, or a foothold for further attacks within the organization's internal network. This flaw is reportedly being actively exploited in the wild.
Technical details
A critical deserialization vulnerability (CWE-502) exists in Microsoft SharePoint Server. The flaw stems from the improper handling of untrusted data during deserialization, which allows an attacker to bypass security checks and execute arbitrary code. The attack vector is network-based and requires no prior authentication or user interaction (AV:N/AC:L/PR:N/UI:N). Attackers can achieve full system compromise of the affected SharePoint instance. Microsoft has released security updates to address this issue, and CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Microsoft SharePoint Server 2016 Enterprise Edition
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition up to (excluding) 16.0.19127.20442
Timeline
- 2026-01-13: disclosed: Initial disclosure by Microsoft Corporation
- 2026-03-18: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-03-18: exploited: Confirmed active exploitation in the wild
- 2026-04-01: advisory: NVD entry updated with revised CVSS and description details