CVE-2025-21400HighCVSS 8.0

Microsoft SharePoint Server Remote Code Execution Vulnerability

Published
June 3, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution? This attack requires a client to connect to a malicious server, and that could allow the attacker to gain code execution on the client.

How could an attacker exploit the vulnerability? In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.

🎯 Affected products3

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

✅ Remediation

KB5002685 (Security Update) — fixed build 16.0.5487.1000 KB5002678 (Security Update) — fixed build 16.0.10416.20050 KB5002681 (Security Update) — fixed build 16.0.17928.20396

🔗 References (7)