Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-45659 is a high-severity deserialization vulnerability in Microsoft Office SharePoint that allows authorized attackers to execute arbitrary code remotely. The vulnerability affects SharePoint's handling of untrusted serialized data, enabling code execution with CVSS score of 8.8.
ثغرة في Microsoft Office SharePoint تسمح لمهاجم مصرح بتنفيذ أكواد تعسفية عبر الشبكة من خلال فك تسلسل بيانات غير موثوقة. تؤثر الثغرة على آليات معالجة البيانات المسلسلة في SharePoint مما يسمح بتجاوز الحماية.
This vulnerability in Microsoft Office SharePoint allows authorized attackers to execute arbitrary code through deserialization of untrusted data. Organizations using SharePoint for document management and collaboration face significant risk of code execution attacks.
Apply Microsoft security patches immediately. Restrict SharePoint access to authorized users only. Implement network segmentation to limit SharePoint exposure. Monitor SharePoint logs for suspicious deserialization activities. Disable unnecessary SharePoint features and services.
طبق تحديثات الأمان من Microsoft فوراً. قيد الوصول إلى SharePoint للمستخدمين المصرحين فقط. طبق تقسيم الشبكة لتحديد تعرض SharePoint. راقب سجلات SharePoint للأنشطة المريبة. عطل الميزات والخدمات غير الضرورية.