CVE-2026-69724: Microsoft Office SharePoint Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Microsoft Office SharePoint Remote Code Execution Vulnerability
Other sources
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft SharePoint Server Subscription Edition<16.0.20326.20090
16.0.20326.20090
Microsoft Office SharePoint
Microsoft SharePoint Server<16.0.20326.20090
Remediation
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:19 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker must already be authorized to access the affected SharePoint deployment. The vulnerability is remotely exploitable over a network and does not require user interaction.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can allow code execution and may result in high impact to confidentiality, integrity, and availability.
3
Which products are identified as affected?
The affected software listed is Microsoft SharePoint Server Subscription Edition and Microsoft Office SharePoint.