HarborGuard / CVE
Back to search
HIGHCVE-2026-20951Published Modified CNA microsoft

CVE-2026-20951: Microsoft SharePoint Server Remote Code Execution Vulnerability

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
16.0.5535.1001
Affected Products
3

Fix available

16.0.5535.100116.0.10417.2008316.0.19127.20442
Affected packages
  • Microsoft / Microsoft SharePoint Enterprise Server 2016
    < 16.0.5535.1001 (from 16.0.0)
  • Microsoft / Microsoft SharePoint Server 2019
    < 16.0.10417.20083 (from 16.0.0)
  • Microsoft / Microsoft SharePoint Server Subscription Edition
    < 16.0.19127.20442 (from 16.0.0)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CVE-2026-20951: Microsoft SharePoint Server Remote Code Execution Vulnerability | HarborGuard CVE