CVE-2026-26106: Microsoft SharePoint Server Remote Code Execution Vulnerability
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft SharePoint Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26106?
The severity of CVE-2026-26106 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2026-26106?
To fix CVE-2026-26106, you should apply the relevant security patches provided by Microsoft for your affected SharePoint Server version.
Which versions of SharePoint Server are affected by CVE-2026-26106?
CVE-2026-26106 affects Microsoft SharePoint Server 2019, SharePoint Server Subscription Edition, and SharePoint Enterprise Server 2016.
What is the impact of CVE-2026-26106 if exploited?
If exploited, CVE-2026-26106 can allow an unauthorized attacker to execute arbitrary code on the server remotely.
Is it necessary to update immediately for CVE-2026-26106?
Yes, it is necessary to update immediately for CVE-2026-26106 to protect your systems from potential exploitation.