CVE-2026-33112Disclosure(microsoft / sharepoint_server)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch microsoft sharepoint_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 6 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 12 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-07-24)
  • 13 total mentions across 6 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline13 mentions / 6d
01234Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-06-30: 1Mentions · 2026-07-07: 3Mentions · 2026-07-08: 3Mentions · 2026-07-24: 4PoC Mentioned / Linked · 2026-07-07: 3PoC Mentioned / Linked · 2026-07-08: 2Exploit Tool / Code · 2026-07-08: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-07-07: 2Patch / Workaround · 2026-07-08: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-07-07: 3Technical Details · 2026-07-08: 3Technical Details · 2026-07-24: 405-1205-1306-3007-0707-0807-24
Signal classification5 categories
Disclosure
538.5%
PoC
430.8%
Patch
215.4%
General
17.7%
Disclose
17.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-05-131
Patch1
2026-06-301
General1
2026-07-073
Disclosure1PoC2
2026-07-083
Disclosure1PoC2
2026-07-244
Disclose1Disclosure3
Full discourse13 posts
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A SharePoint remote code execution flaw (CVE-2026-33112) is now public with full details and PoC. A low-privilege user can run code. Patch now. #SharePoint #RCE #CVE202633112 #Microsoft #CyberSecurity https://securityonline.info/sharepoint-remote-code-execution-cve-2026-33112/

    Post summary

    The post announces CVE‑2026‑33112, a SharePoint RCE, is publicly disclosed with full details and a PoC, notes that low‑privilege users can run code, and that a patch is now available.

    016054183.5K
    12.9K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-33112: Microsoft SharePoint Server Remote Code Execution Vulnerability Critical Vulnerability Alert! Microsoft SharePoint is affected by CVE-2026-33112. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-33112 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-33112" Search Dork: app="Microsoft SharePoint" Exposure: 164.2k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJNaWNyb3NvZnQgU2hhcmVQb2ludCI=&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260708 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet announces a critical RCE in Microsoft SharePoint (CVE‑2026‑33112) and provides links for detailed analysis, highlighting a large number of exposed instances via ZoomEye, but it offers no exploit, patch, or false‑positive information.

    21302763.2K
    12.7K followersView on X
  • Khoa Dinh@_l0gg
    Patch

    Microsoft released fix for CVE-2026-33112. Site Member permissions could execute code remotely on the SharePoint Server. I'm writing a blog for it. https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33112

    Post summary

    Microsoft has released a patch for CVE‑2026‑33112, a vulnerability that allows remote code execution via Site Member permissions on SharePoint Server, and the text references the Microsoft security advisory.

    2002951.8K
    2.2K followersView on X
  • Khoa Dinh@_l0gg
    General

    blog for CVE-2026-33112, you can use it for SafeControls bypass too, but it will require outbound https://blog.viettelcybersecurity.com/cve-2026-33112/

    Post summary

    The referenced blog mentions CVE-2026-33112 and suggests it can be used for a SafeControls bypass, but provides no concrete exploit details, PoC links, patch information, or evidence of active exploitation.

    0711484.2K
    2.2K followersView on X
  • yousukezan@yousukezan
    PoC

    SharePointのリモートコード実行脆弱性CVE-2026-33112について、技術詳細とPoCが公開された。低権限ユーザーでもサーバー上でコードを実行でき、Microsoftは5月のPatch Tuesdayで修正している。 CVE-2026-33112はCVSS 8.8で、オンプレミスのSharePoint Serverに影響する。管理者権限は不要で、サイトメンバーのアカウントがあれば攻撃できるため、侵入済みアカウントからサーバー制御へ進む経路になり得る。 Viettel Cyber Securityの分析によると、この問題は過去のCVE-2025-53770に対する修正を迂回するものだ。攻撃者はXSDスキーマのimportを悪用し、自分のサーバー上に悪意ある外部スキーマを置く。XmlValidatorはインラインのスキーマ文字列だけを検査し、外部スキーマを確認しない。 そのため、外部スキーマ経由で禁止された型を検証処理の外から持ち込み、PerformancePoint Webサービスがペイロードをデシリアライズしてコード実行に至る。報告者はkhoadha氏とされる。 影響を受けるのは2026年5月のセキュリティ更新より前のオンプレミスSharePoint Serverで、SharePoint OnlineはMicrosoftが管理するため利用者側の対応は不要だという。記事は、公開PoCがあるとして、5月更新の適用と、信頼できないホストへのサーバーからの外向き通信遮断を挙げている。 https://securityonline.info/sharepoint-remote-code-execution-cve-2026-33112/

    Post summary

    CVE-2026-33112 was disclosed with technical details and a publicly available PoC; Microsoft’s May Patch Tuesday applied a fix and additional mitigations are recommended.

    0301071.7K
    14.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: 🚨 CVE-2026-33112: Microsoft SharePoint Server Remote Code Execution Vulnerabili

    Post summary

    The post announces a new CVE (CVE‑2026‑33112) for Microsoft SharePoint Server, noting it is a Remote Code Execution vulnerability but providing no additional technical details, PoC, or patch information.

    1000061
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclose

    Source: X search for CVE-2026 critical Posted: 2026-07-08T06:18:25.000Z Likes: 15 0day Intel: 🚨 CVE-2026-33112: Microsoft SharePoint Server Remote Code Execution Vulnerabili

    Post summary

    The tweet announces a new critical CVE-2026-33112 affecting Microsoft SharePoint Server with a remote code execution flaw, but provides no evidence of exploitation, mitigation, or proof of concept.

    1000066
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Full Tweet 🚨 CVE-2026-33112: Microsoft SharePoint Server Remote Code Execution Vulnerability 0day Intel: 🚨 CVE-2026-33112: Microsoft SharePoint Server Remote Code Execution Vulnerabili

    Post summary

    The tweet announces a newly disclosed remote code execution vulnerability (CVE-2026-33112) affecting Microsoft SharePoint Server.

    1000071
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-33112: 🚨 CVE-2026-33112: Microsoft SharePoint Server Remote Code Execution Vulnerability Critical Vulnerability Alert! Microsoft SharePoint is affected by CVE-2026-33112. Full Vulnerability Details & Analysis at DarkEye: 🔗 🔍 Identify…

    Post summary

    The post announces a critical remote code execution vulnerability (CVE-2026-33112) affecting Microsoft SharePoint Server, offering a link to full details but providing no PoC, exploit, patch, or evidence of active exploitation.

    1000068
    326 followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2026-33112 SharePoint RCE is Patch Tuesday’s way of saying “that workflow you forgot is now a risk.” On-prem admins: patch fast before attackers find the dusty auth paths. #Windows #Security https://windowsforum.com/threads/cve-2026-33112-sharepoint-rce-why-patch-tuesday-matters-for-on-prem-admins.417915/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #RemoteCodeExecution #SharepointServer #PatchTuesday https://t.co/XjTAUm8Csc

    Post summary

    The post emphasizes the need for on‑prem SharePoint administrators to apply the Patch Tuesday update for CVE‑2026‑33112, a Remote Code Execution vulnerability, before attackers can exploit the exposed authentication paths.

    0100065
    1.1K followersView on X
  • キタきつね@foxbook
    PoC

    SharePointのリモートコード実行の脆弱性CVE-2026-33112:詳細と概念実証(PoC)が公開されました SharePoint Remote Code Execution Flaw CVE-2026-33112: Details and PoC Public #DailyCyberSecurity (Jul 7) https://securityonline.info/sharepoint-remote-code-execution-cve-2026-33112/

    Post summary

    The post announces that a proof‑of‑concept for the SharePoint RCE vulnerability CVE‑2026‑33112 is now publicly available, with no indication of active exploitation or patch information.

    00000285
    4.9K followersView on X
  • Israel@f1tym1
    Disclosure

    Critical SharePoint RCE flaw CVE-2026-33112 allows low-privilege users to execute arbitrary code by bypassing XmlValidator security control https://ift.tt/9S6ENhv

    Post summary

    The text announces the discovery of CVE-2026-33112, a critical SharePoint RCE that lets low-privilege users execute code by bypassing XmlValidator security controls.

    0000051
    999 followersView on X
  • TECHEPAGES@techepages
    PoC

    ⚠️ A public PoC exploit has been released for CVE-2026-33112, a critical SharePoint RCE vulnerability that bypasses Microsoft's XmlValidator security control. 🔹 Any low-privilege authenticated site member can trigger it — no elevated access needed 🔹 It's a fresh bypass of Microsoft's second patch for CVE-2025-53770's deserialization chain 🔹 Attack abuses external XSD schema imports fetched over the network, blinding validation 🔹 Mitigate: patch urgently, monitor outbound SharePoint traffic & restrict _vti_bin access

    Post summary

    A public PoC exploit for CVE‑2026‑33112, a critical SharePoint RCE that bypasses Microsoft’s XmlValidator, has been released; urgent patching and specific mitigations are recommended.

    00000103
    19 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more