Junglewise Threat Intelligence

CVE-2026-33112: Microsoft SharePoint deserialization of untrusted data

CVE-2026-33112 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Server 2016 Enterprise Edition. Vendors: Microsoft.

Executive brief

Microsoft SharePoint, a widely used platform for document management and team collaboration, contains a security flaw that could allow an authorized user to take control of the server. By sending specially crafted data to the system, an attacker with basic user permissions can execute unauthorized commands. This could lead to the theft of sensitive corporate data, disruption of business operations, or further compromise of the internal network.

Technical details

A deserialization vulnerability (CWE-502) exists in Microsoft SharePoint Server due to the improper handling of untrusted data. An attacker must be authenticated to the SharePoint environment with at least low-privileged user permissions to exploit this flaw. By sending a specially crafted network request containing serialized objects, the attacker can trigger the execution of arbitrary code in the context of the SharePoint service account. This vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition. Microsoft has released security updates to address this issue by improving how SharePoint validates serialized data.

Affected products

  • Microsoft SharePoint Server 2016 Enterprise Edition
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition up to (excluding) 16.0.19725.20280

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft released the security update guide for this vulnerability.

References

Related threats