CVE-2026-69268: Microsoft Office SharePoint Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft Office SharePoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft Office SharePoint
Microsoft SharePoint Server Subscription Edition<16.0.20326.20090
16.0.20326.20090
Microsoft SharePoint Server<16.0.20326.20090
Remediation
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authorized, meaning they need valid access to the affected SharePoint environment. Exploitation can be performed over the network and does not require user interaction.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can allow remote code execution. The supplied severity metrics indicate high impact to confidentiality, integrity, and availability.
3
Which products are identified as affected?
The affected software listed is Microsoft Office SharePoint and Microsoft SharePoint Server Subscription Edition.