CVE-2026-64901

Office: Deserialization of Untrusted Data (CVE-2026-64901)

Affected

  • Microsoft/SharePoint Enterprise Server 2016..*
  • Microsoft/SharePoint Server Subscription Edition..*
  • Microsoft/SharePoint Online..*
  • Microsoft/Teams for iOS..*
  • Microsoft/Teams for Android..*
  • Microsoft/Word 2016..*
  • Microsoft/Access 2016..*
  • Microsoft/Azure SQL Managed Instance..*
  • Microsoft/Excel 2016..*
  • Microsoft/Office 2016..*
  • Microsoft/Office LTSC for Mac 2021..*
  • Microsoft/Office LTSC 2021..*
  • Microsoft/Office LTSC for Mac 2024..*
  • Microsoft/Office LTSC 2024..*
  • Microsoft/Office 2019..*
  • Microsoft/Office 365 for Mac..*
  • Microsoft/OneDrive for MacOS..*
  • Microsoft/Outlook 2016..*
  • Microsoft/PowerPoint 2016..*
  • Microsoft/Service Bus Azure Service Bus..*

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

MicrosoftAccess
2016
MicrosoftAzure
SQL Managed Instance
MicrosoftExcel
2016
MicrosoftOffice
20162019LTSC 2021LTSC 2024LTSC for Mac 2021LTSC for Mac 2024
MicrosoftOffice 365
for Mac
MicrosoftOneDrive
for MacOS
MicrosoftOutlook
2016
MicrosoftPowerPoint
2016
MicrosoftService Bus
Azure Service Bus
MicrosoftSharePoint
Enterprise Server 2016OnlineServer Subscription Edition
MicrosoftTeams
for Androidfor iOS
MicrosoftWord
2016

Metrics

8.8
Source: nvd-v3
80.6 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
high
no public PoC known
2.0 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-11 17:06 UTC
CWE-502

Weakness classes (CWE)

  • CWE-502Base

    Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-08-11 20:54 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.19725.20522
    • Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64901 Types: Patch, Vendor Advisory
  2. CVE Modified2026-08-11 20:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-64901","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
    • Affected: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
    • Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-502

Linked advisories