Junglewise Threat Intelligence

CVE-2026-66805: Microsoft Office SharePoint deserialization of untrusted data

CVE-2026-66805 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint contains a vulnerability in how it handles serialized data from network sources. An authorized attacker can exploit this flaw to execute arbitrary code on the SharePoint server, potentially compromising sensitive business documents and disrupting collaboration across the organization.

Technical details

The vulnerability exists in Microsoft Office SharePoint's deserialization functionality, which improperly handles untrusted serialized data received over the network. The flaw allows an authorized attacker with network access to craft malicious serialized payloads that trigger arbitrary code execution on the affected SharePoint server. This is a classic insecure deserialization vulnerability (CWE-502) where untrusted input is deserialized without proper validation. The attack requires the attacker to have authorization to interact with the vulnerable component, limiting exposure but still posing a significant risk to compromised or disgruntled insiders. Patches are expected to be available through Microsoft's standard security update process.

Affected products

  • Microsoft Office SharePoint <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats