ZeroHour

CVE-2026-33112

mass

Authenticated Deserialization RCE in Microsoft SharePoint Server

CVSS 3.1
8.8 high
EPSS
33%p98
Published
()
Modified
AI analysis

CVE-2026-33112 is an insecure deserialization flaw (CWE-502) in Microsoft Office SharePoint, the on-premises SharePoint Server product. A low-privileged, authorized (authenticated) user can send maliciously crafted serialized data to the server over the network with no user interaction required, causing the server to execute attacker-controlled code. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, potentially compromising the SharePoint farm and its underlying web servers for further lateral movement. Any organization running self-hosted SharePoint Server is affected, particularly farms that expose authenticated access (e.g., SharePoint web services) to the internet. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, and it is not yet in CISA KEV, but the elevated EPSS score (32.7% probability of exploitation within 30 days, 98th percentile) indicates a heightened likelihood of exploitation and warrants prompt patching.

What to do: Apply Microsoft's security update for CVE-2026-33112 to all SharePoint Server farms as soon as the patch is released, prioritizing internet-facing servers, and check Microsoft's advisory for the exact affected versions. Until patched, restrict authenticated access to the farm, remove or minimize direct internet exposure of SharePoint endpoints, and monitor server logs for anomalous authenticated activity given the elevated EPSS. Verify in SharePoint Central Administration or the patch catalog that your farm's build includes the CVE-2026-33112 fix.

Affected
Microsoft SharePoint Server
Estimated exposure
mass≈100,000+ internet-exposed SharePoint Server instances (public scan estimates), with a much larger on-premises installed base behind firewalls — Public internet scan counts published during the 2025 SharePoint Server RCE incident wave put directly internet-exposed SharePoint instances in the low hundreds of thousands, and enterprise on-premises deployments of SharePoint Server are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.