Junglewise Threat Intelligence

CVE-2026-35439: Microsoft SharePoint insecure deserialization remote code execution

CVE-2026-35439 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Server 2016 Enterprise Edition. Vendors: Microsoft.

Executive brief

Microsoft SharePoint, a widely used collaboration and document management platform, contains a security flaw that could allow an authorized user to run malicious code on the server. By exploiting this vulnerability, an attacker with basic user permissions could potentially gain full control over the SharePoint environment, leading to the theft of sensitive corporate data or disruption of business operations. Organizations should apply the latest security updates from Microsoft to protect their internal networks.

Technical details

A deserialization vulnerability (CWE-502) exists in Microsoft SharePoint Server due to improper handling of untrusted data. An attacker with Site Member permissions or higher can exploit this by sending a specially crafted network request to a vulnerable SharePoint instance. Successful exploitation allows for remote code execution (RCE) in the context of the SharePoint service account. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition; Microsoft has released security updates to address this issue.

Affected products

  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server 2016 Enterprise Edition
  • Microsoft SharePoint Server Subscription Edition up to (excluding) 16.0.19725.20280

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft
  • 2026-05-12: advisory: MSRC advisory published
  • 2026-05-13: other: NVD analysis and CPE mapping updated

References

Related threats