CVE-2026-47294ImportantRevised 10 Jun
Microsoft SharePoint Server Remote Code Execution Vulnerability
Assessment
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Severity
- Important
- CVSS base score
- 8.0CVSS:3.1/
AV:N/ AC:L/ PR:L/ UI:R/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Remote Code Execution
- EPSS, next 30 days
- 1.2%Higher than 67.2% of scored CVEs · FIRST model run 29 Sep 2026 · about EPSS
- Public exploit code
- No Nuclei template lists it
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Office SharePoint
- Weakness
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Issued by
- Microsoft
- Published
- 29 May 2026 · May 2026
- Last revised
- 10 Jun 2026Updated an acknowledgement. This is an informational change only.
Updates that fix it
3 KBs| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5002863 | Security Update | — | Microsoft SharePoint Server Subscription Edition | All CVEs in KB5002863 |
| KB5002868 | Security Update | — | Microsoft SharePoint Enterprise Server 2016 | All CVEs in KB5002868 |
| KB5002870 | Security Update | — | Microsoft SharePoint Server 2019 | All CVEs in KB5002870 |