CVE-2026-64901
Office: Deserialization of Untrusted Data (CVE-2026-64901)
highEPSS 2.0%
Affected
- Microsoft/SharePoint
Enterprise Server 2016..* - Microsoft/SharePoint
Server Subscription Edition..* - Microsoft/SharePoint
Online..* - Microsoft/Teams
for iOS..* - Microsoft/Teams
for Android..* - Microsoft/Word
2016..* - Microsoft/Access
2016..* - Microsoft/Azure
SQL Managed Instance..* - Microsoft/Excel
2016..* - Microsoft/Office
2016..* - Microsoft/Office
LTSC for Mac 2021..* - Microsoft/Office
LTSC 2021..* - Microsoft/Office
LTSC for Mac 2024..* - Microsoft/Office
LTSC 2024..* - Microsoft/Office
2019..* - Microsoft/Office 365
for Mac..* - Microsoft/OneDrive
for MacOS..* - Microsoft/Outlook
2016..* - Microsoft/PowerPoint
2016..* - Microsoft/Service Bus
Azure Service Bus..*
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
MicrosoftAccess
2016MicrosoftAzure
SQL Managed InstanceMicrosoftExcel
2016MicrosoftOffice
20162019LTSC 2021LTSC 2024LTSC for Mac 2021LTSC for Mac 2024MicrosoftOffice 365
for MacMicrosoftOneDrive
for MacOSMicrosoftOutlook
2016MicrosoftPowerPoint
2016MicrosoftService Bus
Azure Service BusMicrosoftSharePoint
Enterprise Server 2016OnlineServer Subscription EditionMicrosoftTeams
for Androidfor iOSMicrosoftWord
2016Metrics
80.6 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
high
120.99
no public PoC known
8.8
Published
2026-08-11 17:06 UTC
CWE-502
Weakness classes (CWE)
CWE-502Base
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-11 20:54 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.19725.20522
- Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64901 Types: Patch, Vendor Advisory
- CVE Modified2026-08-11 20:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-64901","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
- Affected: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
- Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-502