CVE-2026-69282: Microsoft Office SharePoint Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft Office SharePoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft SharePoint Server Subscription Edition<16.0.20326.20090
16.0.20326.20090
Microsoft SharePoint Server<16.0.20326.20090
Remediation
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires an authorized attacker, meaning the attacker must have valid access to the affected SharePoint environment. The vulnerability is reachable over a network and does not require user interaction.
2
What is the potential impact if exploitation succeeds?
An attacker can execute code on the affected Microsoft SharePoint Server Subscription Edition system. The listed impact includes high confidentiality, integrity, and availability impact.