CVE-2026-33112
massAuthenticated Deserialization RCE in Microsoft SharePoint Server
CVE-2026-33112 is an insecure deserialization flaw (CWE-502) in Microsoft Office SharePoint, the on-premises SharePoint Server product. A low-privileged, authorized (authenticated) user can send maliciously crafted serialized data to the server over the network with no user interaction required, causing the server to execute attacker-controlled code. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, potentially compromising the SharePoint farm and its underlying web servers for further lateral movement. Any organization running self-hosted SharePoint Server is affected, particularly farms that expose authenticated access (e.g., SharePoint web services) to the internet. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, and it is not yet in CISA KEV, but the elevated EPSS score (32.7% probability of exploitation within 30 days, 98th percentile) indicates a heightened likelihood of exploitation and warrants prompt patching.
What to do: Apply Microsoft's security update for CVE-2026-33112 to all SharePoint Server farms as soon as the patch is released, prioritizing internet-facing servers, and check Microsoft's advisory for the exact affected versions. Until patched, restrict authenticated access to the farm, remove or minimize direct internet exposure of SharePoint endpoints, and monitor server logs for anomalous authenticated activity given the elevated EPSS. Verify in SharePoint Central Administration or the patch catalog that your farm's build includes the CVE-2026-33112 fix.
| Microsoft SharePoint Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.