Junglewise Threat Intelligence

CVE-2026-66808: Microsoft Office SharePoint deserialization code execution

CVE-2026-66808 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint Server is a collaboration platform used by enterprises to manage documents and team content. A flaw in how SharePoint processes untrusted data allows an authenticated attacker to execute arbitrary code on servers, potentially compromising sensitive business documents and enabling lateral movement through corporate networks.

Technical details

The vulnerability stems from unsafe deserialization of untrusted data in Microsoft Office SharePoint. An authenticated attacker with network access can send specially crafted serialized objects that, when deserialized by the SharePoint application, trigger remote code execution. This is a pre-authentication attack requiring valid credentials but no additional user interaction. Successful exploitation grants the attacker the ability to execute arbitrary commands with the privileges of the SharePoint service account.

Affected products

  • Microsoft Office SharePoint <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats