Sceawere

Vulnerability Detail

CVE-2026-65658UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office SharePoint Deserialization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
Attack Type
CWE-502: Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-11T17:18:53.957Z",
  "pubdate": "2026-08-11T17:18:53.957Z",
  "executiveSummary": "A deserialization of untrusted data vulnerability exists in Microsoft Office SharePoint, exposing enterprise environments to severe security risks.\nThe vulnerability allows an authorized remote attacker to execute arbitrary code over the network, bypassing standard security boundaries.\nSuccessful exploitation compromises the integrity, confidentiality, and availability of the affected system, potentially leading to full system takeover.\nThe flaw stems from the insecure handling and processing of serialized objects within the application logic.\nAttackers must possess authorization and network access to target the vulnerable SharePoint deployment, after which malicious payloads can be injected to trigger arbitrary code execution.\nOrganizations relying on Microsoft Office SharePoint face significant risk if appropriate security updates or hardening measures are not promptly applied, as successful exploitation enables threat actors to execute arbitrary commands with the privileges of the SharePoint service account.",
  "technicalDetails": "The vulnerability resides in the deserialization routines of Microsoft Office SharePoint when processing untrusted input data.\nThe root cause is the lack of proper input validation and type restriction during the deserialization process, allowing an attacker to supply specially crafted serialized objects.\nWhen SharePoint ingests and deserializes these malicious payloads, the underlying application framework instantiates arbitrary classes and invokes methods defined within the payload.\nThe attack vector is network-based, requiring the attacker to have network connectivity to the SharePoint endpoint and valid authorization credentials.\nThe exploitation method involves crafting a serialized data structure containing gadget chains that trigger arbitrary code execution upon instantiation.\nThe attack flow proceeds as follows: First, the authorized attacker formulates a malicious serialized payload designed to leverage known classes within the application classpath. Second, the payload is transmitted across the network to the vulnerable Microsoft Office SharePoint service via an exposed interface or protocol. Third, the SharePoint component deserializes the incoming data without adequate validation. Fourth, the malicious gadget chain executes during or immediately after the deserialization process. Finally, the embedded commands run within the context of the SharePoint process, granting the attacker the ability to perform unauthorized operations, pivot deeper into the network, or deploy persistent post-exploitation mechanisms.\nPrivilege requirements mandate that the attacker is an authorized user, though specific administrative privileges may not be required depending on the accessible endpoints that process untrusted serialized data.\nThe affected component is the serialization/deserialization subsystem within Microsoft Office SharePoint."
}
CVE-2026-65658: Microsoft Office SharePoint Deserialization Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere