CVE-2026-69804: Microsoft Office SharePoint Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Microsoft Office SharePoint Remote Code Execution Vulnerability
Other sources
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft SharePoint Server Subscription Edition<16.0.20326.20090
16.0.20326.20090
Microsoft Office SharePoint
Microsoft SharePoint Server<16.0.20326.20090
Remediation
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:19 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires an authorized attacker with low privileges. The vulnerability can be exploited over a network and does not require user interaction.
2
What is the potential impact of successful exploitation?
Successful exploitation could allow code execution and has high impacts on confidentiality, integrity, and availability.
3
Which SharePoint products are identified as affected?
The affected software list identifies Microsoft SharePoint Server Subscription Edition and Microsoft Office SharePoint.