PT-2026-2760 · Microsoft · Sharepoint Server

Published

2026-01-13

·

Updated

2026-05-18

·

CVE-2026-20963

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SharePoint Enterprise Server 2016 SharePoint Server 2019 SharePoint Server Subscription Edition
Description Microsoft Office SharePoint contains a flaw involving the deserialization of untrusted data. Deserialization is the process of converting data from a format like XML or JSON back into an object that a program can use. This issue allows an unauthenticated remote attacker to execute arbitrary code over a network without requiring user interaction by sending a crafted request to the server. Real-world exploitation of this flaw has been confirmed.
Recommendations Apply the security updates released in January for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.

Fix

RCE

DoS

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2026-00638
CVE-2026-20963

Affected Products

Sharepoint Server