<< Back
CVE Number Vulnerability Product Severity Date
CVE-2026-64921 Microsoft SharePoint Server Elevation of Privilege Vulnerability Microsoft SharePoint Critical 01-09-2026

Technical Information

An authenticated attacker with domain access can exploit a missing authentication check for a critical function over a network to execute code remotely on the SharePoint server and elevate privileges to SharePoint administrator.

Patch release date: Aug 11, 2026
Further information on this vulnerability is available at : CVE-2026-64921

Affected Software

Microsoft SharePoint Enterprise Server 2016,
Microsoft SharePoint Server 2019,
Microsoft SharePoint Server Subscription Edition