ZeroHour

CVE-2026-69268

mass

Improper Access Control Leading to Remote Code Execution in Microsoft SharePoint Server

CVSS 3.1
8.8 high
EPSS
<1%p52
Published
()
Modified
AI analysis

CVE-2026-69268 is an improper access control flaw (CWE-284) in Microsoft's on-premises SharePoint Server that allows an authorized attacker to execute code over the network. It is triggered remotely by an attacker who already holds valid low-privileged credentials on the deployment (AV:N/AC:L/PR:L with no user interaction required). Successful exploitation yields remote code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 8.8 High). The CPE data identifies SharePoint Server (on-premises) as affected; SharePoint Online/Microsoft 365 is not listed, and the exact affected version ranges are not included in the available data, so Microsoft's advisory should be consulted. There is currently no public proof-of-concept, the issue is not in CISA's KEV, and EPSS assigns a 0.7% probability of exploitation within 30 days, so no in-the-wild exploitation is known.

What to do: Apply the SharePoint Server security update referenced for CVE-2026-69268 in Microsoft's advisory as soon as it is published, checking the advisory for the exact affected and fixed versions. Because exploitation requires an authorized account, enforce MFA on accounts with SharePoint access, review recently created or modified accounts for unauthorized access, and restrict network exposure of SharePoint servers (e.g., VPN or firewall rules). With no public PoC or KEV entry yet, keep monitoring Microsoft's guidance and EPSS/KEV status, noting that SharePoint RCE-class flaws have historically been weaponized quickly.

Affected
Microsoft SharePoint Server (Microsoft Office SharePoint, on-premises)
Estimated exposure
mass≈100,000 organizations run on-premises SharePoint Server, with tens of thousands of instances internet-exposed — Microsoft cited roughly 100,000 organizations still using on-premises SharePoint Server during the July 2025 SharePoint RCE incidents, and public internet scans around that time found tens of thousands of exposed instances, so total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.