HIGH

CVE-2026-45659

Microsoft Sharepoint Server 2026-05-22 CVSS v3.1
CVSS
8.8
KEV

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Summary dbcve.org

Microsoft Office SharePoint contains a deserialization vulnerability where processing of untrusted serialized data allows an authenticated attacker to execute arbitrary code remotely over a network.

Mitigation

Apply Microsoft security updates for SharePoint to address the deserialization flaw; if patches are unavailable, restrict SharePoint permissions and monitor for anomalous deserialization activity.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

76.08%
Probability of exploitation in next 30 days
99.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE