ZeroHour

CVE-2026-69465

large

Missing Authorization Allows Authenticated RCE in Microsoft SharePoint Server

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69465 is a missing authorization flaw (CWE-862) in Microsoft Office SharePoint, specifically SharePoint Server. An attacker who already holds valid, low-privileged credentials can send a crafted network request to the server, and because the application fails to properly verify permissions, the request results in arbitrary code execution. Successful exploitation gives the attacker code execution on the server with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8 High), with no user interaction required. Organizations running on-premises SharePoint Server are affected; the specific version ranges are not stated in the available data. There is currently no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not listed in CISA KEV, with EPSS estimating a 0.8% chance of exploitation within 30 days.

What to do: Apply the SharePoint Server security update that addresses this CVE as published in Microsoft's Patch Tuesday release (consult the Microsoft Security Update Guide for the exact KB and affected versions). Until patched, reduce exposure by limiting which accounts can reach SharePoint externally (VPN/extranet access) and monitoring authenticated requests for anomalous activity. Since exploitation requires an authorized account, review whether low-privileged or external users have access to internet-facing SharePoint servers.

Affected
microsoft sharepoint server
Estimated exposure
largetens of thousands of internet-exposed SharePoint Server instances, plus far more internal-only deployments — Public internet scans (e.g., Shodan-style data) typically show tens of thousands of exposed SharePoint Server front ends, and on-prem SharePoint remains common in mid-size and large enterprises, though exploitation requires valid…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft's September Patch Tuesday fixed a record 974 flaws, including two Windows privilege-escalation zero-days actively exploited and added to CISA's KEV catalog.

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities (999 including 25 non-Microsoft CVEs), with over 110 rated critical; 723 affect Windows and 111 affect Office. Two Windows privilege-escalation zero-days are actively exploited: CVE-2026-85880, an ALPC heap-based buffer overflow, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack, both allowing attackers to gain SYSTEM privileges. CISA added both flaws to its KEV catalog, giving federal civilian agencies until September 22, 2026 to apply fixes. Volexity, Proofpoint, MSTIC, and independent researchers were credited with the reports; notable additional fixes include network-reachable RCEs in Exchange, SharePoint, SQL Server, Remote Desktop Services, DNS, and DHCP.

The Hacker News · 6d agoExploit / PoC in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+9 CVEs

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two Windows zero-days exploited in the wild for privilege escalation.

Microsoft patched 974 vulnerabilities, its largest Patch Tuesday ever, including CVE-2026-85880, a heap buffer overflow in Windows ALPC allowing AppContainer sandbox escape to System, and CVE-2026-81963, a link-following flaw in the Windows Update Stack enabling local privilege escalation. Both were exploited as zero-days before the patch. ZDI's Dustin Childs says 20 of the fixed flaws are wormable, enabling unauthenticated remote code execution. The release also covers 723 Windows flaws and 222 Office bugs, plus fixes in Exchange, SharePoint, SQL Server, Azure and Exchange Server RCE (CVE-2026-55007).

SecurityWeek · 7d agoExploit / PoC in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+5 CVEs