PT-2026-2760 · Microsoft · Sharepoint Server
Published
2026-01-13
·
Updated
2026-05-18
·
CVE-2026-20963
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SharePoint Enterprise Server 2016
SharePoint Server 2019
SharePoint Server Subscription Edition
Description
Microsoft Office SharePoint contains a flaw involving the deserialization of untrusted data. Deserialization is the process of converting data from a format like XML or JSON back into an object that a program can use. This issue allows an unauthenticated remote attacker to execute arbitrary code over a network without requiring user interaction by sending a crafted request to the server. Real-world exploitation of this flaw has been confirmed.
Recommendations
Apply the security updates released in January for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
Fix
DoS
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharepoint Server