Remote Code Execution Vulnerability in Microsoft Office SharePoint
CVE-2026-33112
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-33112?
CVE-2026-33112 is a remote code execution vulnerability found in Microsoft Office SharePoint, a widely-used platform for collaboration, document management, and content management within organizations. This vulnerability arises from the deserialization of untrusted data, which can be exploited by authorized attackers to execute arbitrary code remotely over a network. The seriousness of this flaw is underscored by its ability to affect systems that utilize SharePoint, offering attackers a pathway to potentially compromise sensitive organizational data and systems. If successfully exploited, the vulnerability can allow for unauthorized control and manipulation of the affected SharePoint instances, posing significant risks to business continuity and data integrity.
Potential impact of CVE-2026-33112
-
Remote Code Execution: The primary impact of this vulnerability is the potential for unauthorized remote code execution, allowing attackers to run malicious code on the affected system. This could lead to significant breaches, including data theft and unauthorized access.
-
Compromised Organizational Integrity: With the ability to execute code remotely, attackers could manipulate or erase critical data, disrupt services, and substantially undermine the trustworthiness of the organization’s operations and data.
-
Increased Attack Surface: Given SharePoint's role in collaboration and the storage of sensitive information, this vulnerability increases the attack surface for organizations, making them more susceptible to further exploits and ransomware attacks, should the initial compromise occur.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5552.1002
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20128
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20280
References
EPSS Score
32% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved