Skip to content
COOEY

FAIL › dossier

SharePoint Server

PRODUCT

· dossier confidence 20%

PROFILE
CategoryProductWhat they doMicrosoft SharePoint Server is a platform for collaboration and document management. Websitehttps://www.microsoft.com/en-us/sharepoint ↗
SECURITY POSTURE

Microsoft SharePoint Server has been identified with multiple critical vulnerabilities that have been actively exploited in the wild.

Notable failures
  • CVE-2023-24955: Remote code execution via code injection vulnerability.
  • CVE-2023-29357: Remote code execution via spoofed JWT tokens.
  • CVE-2026-56164: Remote code execution via deserialization of untrusted data.
  • CVE-2026-45659: Remote code execution via unsafe data processing.
  • CVE-2026-32201: Network spoofing enabling data integrity and trust threats.
  • CVE-2026-50522: Critical deserialization of untrusted data allowing code execution over a network.
Patterns: Repeated unpatched edge-device RCEs.; Chain of authentication bypass, unsafe data processing, and input-validation flaws.
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2024-03-26 CVE-2023-24955 critical An authenticated attacker with Site Owner privileges could remotely execute code via a code injection vulnerability in Microsoft SharePoint Server.
2024-01-10 CVE-2023-29357 critical An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks.
2026-07-14 CVE-2026-56164 high Unpatched RCE in SharePoint Server
2026-07-01 CVE-2026-45659 high Microsoft SharePoint Server allows remote code execution via deserialization of untrusted data.
2026-04-14 CVE-2026-32201 high Microsoft SharePoint Server is actively exploited via CVE-2026-32201, enabling network spoofing that threatens DIB data integrity and trust.
2026-07-14 CVE-2026-56164 medium CVE-2026-56164: Missing authentication for critical function in Microsoft Office SharePoint allo
2023-02-14 CVE-2023-21716 critical CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
Open questions: How has Microsoft addressed these vulnerabilities? · What is the current state of security for SharePoint Server? · How does SharePoint Server's architecture contribute to potential security risks?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-23 03:40:14.465269+00:00