Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-33112: SharePoint XmlValidator Bypass Enables Low-Privilege RCE

Summary

CVE-2026-33112: a network-imported XSD schema bypasses SharePoint's XmlValidator, and the PerformancePoint PPSAuthoringService revives ExcelDataSet deserialization for low-privilege RCE.
Published
Collected

original ↗

Related coverage

back