Back

HIGH KEV

Microsoft SharePoint Server Remote Code Execution Vulnerability

Published Aug 11, 2026 ·Due Sep 28, 2026

Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (32)
  1. CISA ADP
    • SSVC technical impact

      changed from partial to total

    • SSVC exploitation

      changed from none to active

  2. CISA ADP
    • SSVC technical impact

      changed from total to partial

    • SSVC exploitation

      changed from active to none

  3. CISA ADP
    • SSVC technical impact

      changed from partial to total

    • SSVC exploitation

      changed from none to active

  4. CISA ADP
    • SSVC technical impact

      changed from total to partial

    • SSVC exploitation

      changed from active to none

  5. CISA ADP
    • SSVC technical impact

      changed from partial to total

    • SSVC exploitation

      changed from none to active

  6. CISA ADP
    • SSVC technical impact

      changed from total to partial

    • SSVC exploitation

      changed from active to none

  7. CISA ADP
    • SSVC technical impact

      changed from partial to total

    • SSVC exploitation

      changed from none to active

  8. CISA ADP
    • SSVC technical impact

      changed from total to partial

    • SSVC exploitation

      changed from active to none

  9. CISA ADP
    • SSVC exploitation

      changed from none to active

  10. CISA ADP
    • SSVC technical impact

      changed from partial to total

  11. CISA ADP
    • SSVC technical impact

      changed from total to partial

    • SSVC exploitation

      changed from active to none

  12. CISA ADP
    • SSVC exploitation

      changed from none to active

  13. CISA ADP
    • SSVC exploitation

      changed from active to none

  14. CISA ADP
    • SSVC exploitation

      changed from none to active

  15. CISA ADP
    • SSVC exploitation

      changed from active to none

  16. CISA ADP
    • SSVC exploitation

      changed from none to active

  17. CISA ADP
    • SSVC technical impact

      changed from partial to total

  18. CISA ADP
    • SSVC technical impact

      changed from total to partial

  19. CISA ADP
    • SSVC technical impact

      changed from partial to total

  20. CISA ADP
    • SSVC technical impact

      changed from total to partial

  21. CISA ADP
    • SSVC technical impact

      changed from partial to total

  22. CISA ADP
    • SSVC technical impact

      changed from total to partial

  23. CISA ADP
    • SSVC technical impact

      changed from partial to total

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner microsoft
Published Aug 11, 2026
Updated Sep 29, 2026
Reserved Jul 22, 2026

CISA Vulnrichment

Updated Sep 25, 2026

NVD

Status Modified
Modified Aug 27, 2026

Red Hat

No data

ENISA EUVD

Assigner microsoft
Published Aug 11, 2026
Updated Sep 29, 2026
Exploited since Sep 25, 2026

GitHub

No data