CVE-2026-26106Disclosure(microsoft / sharepoint_server)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft sharepoint_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-10); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-10: 2Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-04-25: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-25: 103-1003-1103-1303-1604-25
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-102
Disclosure2
2026-03-111
Patch1
2026-03-131
Disclosure1
2026-03-161
Disclosure1
2026-04-251
General1
Full discourse6 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Deserialization and Improper Input Validation vulnerability in #Microsoft Office SharePoint. CVE-2026-26106 CVE-2026-26114 CVSS 8.8. These vulnerabilities can lead to remote code execution #RCE! #Patch #Patch #Patch

    Post summary

    The tweet issues a warning about two new SharePoint vulnerabilities with high CVSS scores that could lead to RCE, but provides no PoC, exploit code, or patch details.

    03021511
    7.2K followersView on X
  • ✮ Cymon Skinner ✮@CymonSkinner
    Patch

    Microsoft's March 2026 Patch Tuesday addresses 84 vulnerabilities, including two public zero-days that demand immediate attention from CISOs. Prioritise patching critical RCE flaws in Windows RRAS (CVE-2026-25172) and SharePoint (CVE-2026-26106), as these align with common attack paths in real-world breaches. With over 40 elevation of privilege issues, focus your Sentinel triage on exploitation-more-likely CVEs like CVE-2026-24294 in SMB Server. Swift action bridges skills gaps in vulnerability management. #PatchTuesday #Cybersecurity

    Post summary

    The post stresses urgent patching of Microsoft's March 2026 Patch Tuesday vulnerabilities, highlighting two public zero‑day RCE flaws and pointing to many privilege‑escalation issues that need immediate attention.

    0001063
    711 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-26106: Microsoft SharePoint Remote Code Execution Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04dssHs0

    Post summary

    The text announces CVE‑2026‑26106, a SharePoint remote code execution vulnerability, and indicates the article will discuss its business impact and response options, but it does not provide PoC, exploit code, active exploitation evidence, or patch details.

    0000023
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26106 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-26106

    Post summary

    The text provides a disclosure of CVE-2026-26106, explaining it as an input-validation flaw in Microsoft Office SharePoint that permits code execution by authorized attackers. No PoC, exploit code, active exploitation evidence, patch, or debunking is mentioned.

    00000188
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26106 - High Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-26106/ https://t.co/FnQ90NzDti

    Post summary

    CVE-2026-26106 has been disclosed as an improper input validation flaw in Microsoft Office SharePoint that permits authorized users to execute code over the network.

    0000050
    133 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26106: HIGH] Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.#cve,CVE-2026-26106,#cybersecurity https://cvefind.com/CVE-2026-26106

    Post summary

    The post announces CVE-2026-26106, detailing an improper input validation flaw in Microsoft Office SharePoint that permits code execution by authorized users, without providing PoC, exploit, or mitigation information.

    0000033
    601 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more