Junglewise Threat Intelligence

CVE-2026-65658: Microsoft Office SharePoint deserialization of untrusted data

CVE-2026-65658 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint contains a flaw in how it processes data from network requests. An authorized user on the network can send specially crafted requests to cause the application to deserialize and execute malicious code, potentially compromising the entire SharePoint installation and the data it stores.

Technical details

This vulnerability involves insecure deserialization of untrusted data in Microsoft Office SharePoint. An authorized attacker with network access can craft malicious serialized objects that, when deserialized by the application, lead to arbitrary code execution. The attack requires valid credentials and network access to the SharePoint service, but no additional user interaction. Successful exploitation allows remote code execution in the context of the SharePoint application, potentially granting access to sensitive business data and system resources. A patch is expected to be available through Microsoft's regular security update channels.

Affected products

  • Microsoft Office SharePoint <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats