The SentinelOne Annual Threat Report - A Defenders Guide from the FrontlinesThe SentinelOne Annual Threat ReportGet the Report
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-33112

CVE-2026-33112: Microsoft SharePoint Server RCE Vulnerability

CVE-2026-33112 is a remote code execution vulnerability in Microsoft SharePoint Server caused by deserialization flaws. Authorized attackers can exploit this to execute arbitrary code. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published: May 17, 2026

CVE-2026-33112 Overview

CVE-2026-33112 is a deserialization of untrusted data vulnerability [CWE-502] in Microsoft Office SharePoint Server. An authenticated attacker can send a crafted serialized payload over the network to trigger code execution in the SharePoint application context. The flaw affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 Enterprise. Microsoft published the advisory on May 12, 2026, and assigned a CVSS 3.1 base score of 8.8.

Critical Impact

An authorized attacker with low privileges can execute arbitrary code on the SharePoint server, leading to full compromise of confidentiality, integrity, and availability.

Affected Products

  • Microsoft SharePoint Server Subscription Edition
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server 2016 Enterprise

Discovery Timeline

  • 2026-05-12 - Microsoft publishes security update advisory for CVE-2026-33112
  • 2026-05-12 - CVE-2026-33112 published to NVD
  • 2026-05-13 - Last updated in NVD database

Technical Details for CVE-2026-33112

Vulnerability Analysis

The vulnerability resides in SharePoint Server's processing of serialized .NET objects submitted through authenticated user requests. SharePoint deserializes attacker-supplied data without sufficient type validation, allowing crafted gadget chains to invoke arbitrary methods during object reconstruction. Successful exploitation results in remote code execution under the w3wp.exe worker process running the SharePoint web application pool identity.

Microsoft classifies the attack vector as Network with low attack complexity. The attacker must hold a low-privilege authenticated SharePoint account, such as a standard site member, to reach the vulnerable code path. No user interaction is required. EPSS data from May 17, 2026, reflects moderate exploitation likelihood relative to other recently disclosed CVEs.

Root Cause

The root cause is insecure deserialization [CWE-502] of untrusted input within a SharePoint server-side component. The deserializer reconstructs object graphs from attacker-controlled streams without enforcing an allow-list of safe types. This pattern enables gadget chains present in the .NET framework or SharePoint assemblies to trigger code execution during deserialization callbacks such as OnDeserialization or property setters.

Attack Vector

An attacker authenticates to the target SharePoint site with any valid low-privilege account. The attacker sends an HTTP request containing a serialized payload to a vulnerable SharePoint endpoint. SharePoint deserializes the payload server-side and invokes the embedded gadget chain. The chain executes operating system commands or loads additional payloads with the privileges of the SharePoint application pool account.

No verified public proof-of-concept exploit is available at the time of publication. Refer to the Microsoft Security Update CVE-2026-33112 advisory for vendor-supplied technical context.

Detection Methods for CVE-2026-33112

Indicators of Compromise

  • Unexpected child processes spawned by w3wp.exe hosting SharePoint application pools, such as cmd.exe, powershell.exe, or rundll32.exe
  • New or modified files in SharePoint web directories under C:\inetpub\wwwroot\wss\VirtualDirectories\
  • Authenticated HTTP POST requests to SharePoint endpoints containing base64-encoded serialized .NET payloads
  • Outbound network connections from SharePoint servers to unfamiliar external hosts shortly after authenticated requests

Detection Strategies

  • Monitor IIS logs for authenticated requests with abnormally large request bodies or __VIEWSTATE parameters to SharePoint handlers
  • Inspect Windows Event Logs for .NET Runtime errors referencing BinaryFormatter, LosFormatter, or ObjectStateFormatter exceptions
  • Alert on SharePoint application pool identities executing scripting interpreters or performing file writes outside expected directories
  • Hunt for known ysoserial.net gadget signatures, including TypeConfuseDelegate and ActivitySurrogateSelector references, in request payloads

Monitoring Recommendations

  • Enable detailed IIS request logging and forward to a centralized SIEM for correlation across SharePoint farm members
  • Track process lineage from w3wp.exe and baseline expected child processes to surface anomalies
  • Review SharePoint ULS logs for unhandled exceptions originating from deserialization code paths

How to Mitigate CVE-2026-33112

Immediate Actions Required

  • Apply the May 2026 Microsoft security updates for SharePoint Server Subscription Edition, 2019, and 2016 as documented in the Microsoft Security Update CVE-2026-33112 advisory
  • Inventory all SharePoint farms and confirm patch deployment across web front-end, application, and search servers
  • Audit SharePoint user accounts and remove unused or stale low-privilege accounts that could be leveraged for authenticated exploitation
  • Rotate SharePoint farm and service account credentials if compromise is suspected

Patch Information

Microsoft released security updates addressing CVE-2026-33112 on May 12, 2026. Administrators should install the cumulative updates for the affected SharePoint Server editions through Microsoft Update, WSUS, or the Microsoft Update Catalog. Verify patch installation by checking build numbers against the values listed in the vendor advisory.

Workarounds

  • Enforce multi-factor authentication on all SharePoint accounts to reduce the risk of credential-based access to authenticated endpoints
  • Restrict SharePoint access to trusted network segments using web application firewall rules or reverse proxy filters that inspect for serialized payload signatures
  • Run SharePoint application pools under least-privilege service accounts to limit the impact of successful code execution
  • Disable or restrict SharePoint features and web parts not in active use to reduce exposed deserialization surface

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeRCE

  • Vendor/TechMicrosoft Sharepoint

  • SeverityHIGH

  • CVSS Score8.8

  • EPSS Probability0.56%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-502
  • Vendor Resources
  • Microsoft Security Update CVE-2026-33112
  • Related CVEs
  • CVE-2026-35439: Microsoft SharePoint Server RCE Vulnerability

  • CVE-2026-40365: Microsoft SharePoint Server RCE Vulnerability

  • CVE-2026-40368: Microsoft SharePoint Server RCE Vulnerability

  • CVE-2026-40357: Microsoft SharePoint Server RCE Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English