CVE-2026-47294

HIGH WAF: High
CVSS 8.0 Published: 2026-06-01
CWE-78

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
microsoftsharepoint_serverup to 16.0.19725.20280
microsoftsharepoint_server2016
microsoftsharepoint_server2019

References

Back to CVE Database