CVE-2026-63514HighCVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002905 (Security Update) — fixed build 16.0.5565.1001 KB5002906 (Security Update) — fixed build 16.0.5565.1001 KB5002894 (Security Update) — fixed build 16.0.10417.20198 KB5002896 (Security Update) — fixed build 16.0.10417.20198 KB5002893 (Security Update) — fixed build 16.0.19725.20522
🔗 References (11)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63514
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=108758
- referencehttps://support.microsoft.com/help/5002905
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=108776
- referencehttps://support.microsoft.com/help/5002906
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=108774
- referencehttps://support.microsoft.com/help/5002894
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=108773
- referencehttps://support.microsoft.com/help/5002896
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=108767
- referencehttps://support.microsoft.com/help/5002893