Junglewise Threat Intelligence

CVE-2026-64901: Microsoft Office SharePoint deserialization of untrusted data

CVE-2026-64901 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint contains a deserialization vulnerability that allows an authorized attacker to execute arbitrary code remotely over a network. Exploitation could lead to complete compromise of SharePoint servers and access to sensitive business documents and data stored within the platform.

Technical details

The vulnerability exists in the deserialization of untrusted data within Microsoft Office SharePoint. An authorized attacker with network access can craft malicious serialized objects that, when deserialized by the application, execute arbitrary code with the privileges of the SharePoint service. The attack requires authentication but can be executed over the network. Patches are available from Microsoft via their security update guide.

Affected products

  • Microsoft Office SharePoint <UNKNOWN>

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory

References

Related threats