Junglewise Threat Intelligence

CVE-2026-65665: Microsoft Office SharePoint deserialization of untrusted data in network communication

CVE-2026-65665 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint is a collaborative document and content management platform used by organizations to store and share business files and information. This vulnerability allows an authenticated attacker to execute malicious code on servers running SharePoint by sending specially crafted network requests that exploit unsafe deserialization, potentially compromising data confidentiality and system availability.

Technical details

The vulnerability is a deserialization flaw in Microsoft Office SharePoint that permits remote code execution when processing untrusted serialized objects. An authorized attacker can craft malicious serialized data and transmit it over the network to trigger arbitrary code execution on affected SharePoint servers. The attack requires authentication and network connectivity to the vulnerable SharePoint instance. Exploitation allows an attacker to run commands with the privileges of the SharePoint application process. Microsoft has issued security patches to address this vulnerability.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-08-11: disclosed

References

Related threats