Junglewise Threat Intelligence

CVE-2026-33110: Microsoft SharePoint insecure deserialization remote code execution

CVE-2026-33110 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Server 2016 Enterprise Edition. Vendors: Microsoft.

Executive brief

Microsoft SharePoint, a widely used platform for document management and team collaboration, contains a security vulnerability that could allow an authorized user to take control of the server. By sending specially crafted data to the system, an attacker with basic user permissions can execute unauthorized commands. This could lead to the theft of sensitive corporate data, disruption of business operations, or a complete compromise of the SharePoint environment.

Technical details

A remote code execution vulnerability exists in Microsoft SharePoint Server due to the insecure deserialization of untrusted data (CWE-502). An attacker must be authenticated to the target environment with at least Site Member permissions to exploit this flaw. By sending a specially crafted network request containing malicious serialized objects, the attacker can trigger arbitrary code execution in the context of the SharePoint service account. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition. Microsoft has released security updates to address this issue; users should update SharePoint Server Subscription Edition to version 16.0.19725.20280 or later.

Affected products

  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server 2016 Enterprise Edition
  • Microsoft SharePoint Server Subscription Edition up to (excluding) 16.0.19725.20280

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security update guide.

References

Related threats