Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: 2.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Deserialization of untrusted data in Microsoft Office SharePoint Server enables an attacker with authorized SharePoint access to run arbitrary code on the server. The flaw is a classic Deserialization of Untrusted Data weakness (CWE‑502) that can compromise confidentiality, integrity, and availability of corporate assets. The vulnerability permits an attacker to take control over the SharePoint service and potentially pivot to other systems in the network (inferred).

Affected Systems

Affected are Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition. No specific version sub‑range is listed; the issue applies to any installation of these products that has not applied the latest Microsoft security update referenced in the official Microsoft Security Update Guide.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the EPSS score of 3% indicates a low but non‑zero probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting that it is not currently actively exploited. Based on the description, it is inferred that a likely attack requires network access to SharePoint and that the attacker already has authorized SharePoint credentials, after which they can supply crafted payloads that trigger unsafe deserialization.

Generated by OpenCVE AI on August 24, 2026 at 17:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft SharePoint Server security update that addresses CVE-2026-65665 from the Microsoft Security Update Guide.
  • Restrict SharePoint to only allow trusted content sources and disable or remove any custom code that performs deserialization of third‑party data.
  • Monitor SharePoint logs for anomalous execution events and audit user privileges to ensure that only necessary accounts have write access to sites that can trigger deserialization.
  • Configure network perimeter controls to block non‑essential inbound traffic to SharePoint services and isolate the server from untrusted networks.

Generated by OpenCVE AI on August 24, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Thu, 13 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title Microsoft SharePoint Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2019
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:39.975Z

Reserved: 2026-07-22T18:16:01.897Z

Link: CVE-2026-65665

cve-icon Vulnrichment

Updated: 2026-08-11T18:27:26.527Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:54.760

Modified: 2026-08-13T13:36:00.857

Link: CVE-2026-65665

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T17:30:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data