CVE-2026-65663
Microsoft SharePoint Server Remote Code Execution Vulnerability
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-65663 is a Microsoft SharePoint Server flaw where an authorized user can remotely run malicious code on the server; for most small businesses, this is a high concern if SharePoint is exposed to users you don’t fully trust or are credential-compromised.
In Microsoft SharePoint Server 2016/2019/Subscription Edition, CVE-2026-65663 enables Remote Code Execution via incorrect processing of specially crafted network data by an authorized user (CWE-502 deserialization of untrusted data), with no user interaction required.
What to do now
- Check which Microsoft SharePoint Server edition/version you run (2016, 2019, or Subscription Edition) and note the exact build number.
- Compare your build to the fixed builds: 16.0.5565.1001 (SharePoint Enterprise Server 2016), 16.0.10417.20198 (SharePoint Server 2019), and 16.0.19725.20522 (SharePoint Server Subscription Edition / sharepoint server).
- Upgrade SharePoint to the fixed version for your edition as listed by Microsoft (use the MSRC update guidance for CVE-2026-65663).
- If upgrading can’t be done immediately, restrict who can authenticate to SharePoint (and who can access the vulnerable areas) while you plan the patch.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-65663 and every CVE in our database. Create a free account — no credit card required.
Create Free Account