CVE-2026-26114
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Affected products
- Sharepoint Server
- Microsoft Sharepoint Server
- = 2016, 2019
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 3.0% (86th percentile)
- Weakness
- CWE-502
- NVD status
- Analyzed
- Published
- 2026-03-10
CVE-2026-26114 at NVD
1 known exploit for CVE-2026-26114
Proof-of-concept code and exploit modules indexed by Sploitus