Junglewise Threat Intelligence

CVE-2026-40357: Microsoft SharePoint remote code execution via unsafe deserialization

CVE-2026-40357 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019. Vendors: Microsoft.

Executive brief

Microsoft SharePoint is a widely used collaboration and document management platform. A security vulnerability has been identified that allows an authorized user to execute malicious code on the server. This could lead to a complete takeover of the SharePoint environment, resulting in the theft of sensitive corporate data or a total disruption of business operations.

Technical details

A remote code execution vulnerability exists in Microsoft SharePoint Server due to the unsafe deserialization of untrusted data (CWE-502). An attacker with basic user permissions (Site Member or similar) can exploit this by sending a specially crafted network request to the SharePoint server. Successful exploitation allows the attacker to execute arbitrary code in the context of the SharePoint service account. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition; Microsoft has released security updates to address this issue.

Affected products

  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server 2016 Enterprise
  • Microsoft SharePoint Server Subscription Edition up to (excluding) 16.0.19725.20280

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security update guide.

References

Related threats