CVE-2026-26114Disclosure(microsoft / sharepoint_server)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch microsoft sharepoint_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-03-10); latest day: 2
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-03-10: 2Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-04-25: 1Mentions · 2026-07-03: 1Mentions · 2026-07-09: 1Mentions · 2026-07-22: 2PoC Mentioned / Linked · 2026-07-03: 1PoC Mentioned / Linked · 2026-07-22: 2Exploit Tool / Code · 2026-07-03: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-22: 103-1003-1303-1604-2507-0307-0907-22
Signal classification3 categories
Disclosure
444.4%
PoC
333.3%
General
222.2%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-102
Disclosure2
2026-03-131
Disclosure1
2026-03-161
Disclosure1
2026-04-251
General1
2026-07-031
PoC1
2026-07-091
General1
2026-07-222
PoC2
Full discourse9 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-26114 PT ID: PT-2026-24324 Vendor: Microsoft Product: Microsoft SharePoint Enterprise Server 2016 Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Link: https://github.com/huynambka/cve-2026-26114-poc #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑26114 affecting Microsoft SharePoint Enterprise Server 2016 has been released on GitHub, demonstrating deserialization‑based remote code execution.

    143018112334.7K
    3.4K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Deserialization and Improper Input Validation vulnerability in #Microsoft Office SharePoint. CVE-2026-26106 CVE-2026-26114 CVSS 8.8. These vulnerabilities can lead to remote code execution #RCE! #Patch #Patch #Patch

    Post summary

    The post announces two new Microsoft SharePoint vulnerabilities (CVE-2026-26106 and CVE-2026-26114) that allow remote code execution via deserialization and input validation weaknesses, with a CVSS score of 8.8, and urges users to apply patches.

    03021511
    7.2K followersView on X
  • ET Labs@ET_Labs
    General

    13 new OPEN, 23 new PRO (13 + 10) Gitea API Authentication Bypass (CVE-2026-20896), OPNsense Secrets Disclosure via XPATH Injection (CVE-2026-53582), Microsoft SharePoint Taxonomy SQLi (CVE-2026-26114), and more https://community.emergingthreats.net/t/ruleset-update-summary-2026-07-09-v11230/3379

    Post summary

    The post merely lists new CVEs with brief technical labels, without referencing PoCs, exploits, or mitigation details.

    02010334
    5.7K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Source: X search for PoC exploit 2026 Posted: 2026-07-03T17:35:03.000Z Likes: 83 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-26114

    Post summary

    A proof‑of‑concept/exploit for CVE‑2026‑26114 has been discovered, but no detailed exploit code, tool, or patch information is included.

    1000058
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-26114: A PoC/exploit has been discovered for vulnerability CVE-2026-26114 PT ID: PT-2026-24324 Vendor: Microsoft Product: Microsoft SharePoint Enterprise Server 2016 Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized…

    Post summary

    A proof‑of‑concept/exploit has been discovered for CVE‑2026‑26114 affecting Microsoft SharePoint 2016, but no active exploitation, patch, or detailed exploit code is provided.

    1000076
    326 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-26114: Microsoft SharePoint Deserialization Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04dsrJ50

    Post summary

    The post references CVE‑2026‑26114, a Microsoft SharePoint deserialization vulnerability, but offers no specific technical, exploit, or mitigation details.

    0000026
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26114 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-26114

    Post summary

    The text announces a new CVE (CVE-2026-26114) describing a deserialization flaw in Microsoft Office SharePoint that allows authorized attackers to execute code over a network. No proof of concept, exploit code, patch, or active exploitation information is provided.

    00000222
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26114 - High Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-26114/ https://t.co/1f22O3tiWg

    Post summary

    A new CVE-2026-26114 in Microsoft Office SharePoint allows code execution via deserialization of untrusted data; no PoC, exploit code, or active exploitation reported.

    0000045
    133 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26114: HIGH] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.#cve,CVE-2026-26114,#cybersecurity https://cvefind.com/CVE-2026-26114

    Post summary

    Microsoft Office SharePoint suffers a deserialization vulnerability (CVE‑2026‑26114) that can lead to code execution, but no PoC, exploit, patch, or active exploitation info is provided.

    0000047
    601 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more