PatchDay Alert

CVE

CVE-2026-40357

0field notes · 1digest CVSS 8.8


Daily digests

SharePoint deserializes untrusted data, letting an authenticated attacker execute arbitrary code on the server over the network. Any user with legitimate SharePoint access can trigger this. If you run on-prem SharePoint, this is a serious RCE that only requires a low-privilege account to pull off.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.