Junglewise Threat Intelligence

CVE-2026-63514: Microsoft Office SharePoint deserialization code execution

CVE-2026-63514 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint is a widely-used enterprise collaboration and document management platform. A deserialization vulnerability allows an authorized attacker to execute arbitrary code on the server, potentially leading to unauthorized access to sensitive business data, disruption of services, or lateral movement within corporate networks.

Technical details

The vulnerability is a deserialization of untrusted data flaw in Microsoft Office SharePoint that allows authenticated attackers to achieve remote code execution. The attack requires network access and valid authorization credentials to the SharePoint instance. An attacker can craft malicious serialized objects that, when deserialized by the application, trigger arbitrary code execution with the privileges of the SharePoint service account. Patches addressing this vulnerability are available from Microsoft.

Affected products

  • Microsoft Office SharePoint <UNKNOWN>

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory

References

Related threats