Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-66808

CVE-2026-66808: 2 tracked advisory records across MS Server, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

MS Server

1 advisory
  • Advisory severityHigh8.8

    High [CVE-2026-66808] Microsoft SharePoint Server Remote Code Execution Vulnerability

    CVE-2026-66808Source published Source updated

    Microsoft SharePoint Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

    Affected products in this advisory
    • Microsoft SharePoint Enterprise Server 2016
    • Microsoft SharePoint Server 2019
    • Microsoft SharePoint Server Subscription Edition
    Source-reported affected versions
    • Microsoft SharePoint Enterprise Server 2016 16.0.0 before 16.0.5565.1001
    • Microsoft SharePoint Server 2019 16.0.0 before 16.0.10417.20198
    • Microsoft SharePoint Server Subscription Edition 16.0.0 before 16.0.19725.20522
    Source-reported fixed versions
    • KB5002905 (build 16.0.5565.1001)
    • KB5002906 (build 16.0.5565.1001)
    • KB5002894 (build 16.0.10417.20198)
    • KB5002896 (build 16.0.10417.20198)

    1 more entries in the full advisory.

    Mitigation guidance
    • Install the applicable security update for your platform: KB5002905, KB5002906, KB5002894, KB5002896, KB5002893 (see the Microsoft Update Catalog).

Red Hat

1 advisory
  • Advisory severityHigh8.7

    High [CVE-2026-66808] unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)

    CVE-2026-66808Source published Source updated

    unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection). Red Hat rates this important (CVSS 8.7). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/hypershift-addon-rhel9-operator:1786912006, multicluster-engine/hypershift-addon-rhel9-operator:1786548381, multicluster-engine/hypershift-addon-rhel9-operator:1787259113, multicluster-engine/hypershift-addon-rhel9-operator:1787264068. Affected product named by the advisory: Multicluster Engine for Kubernetes.

    Related products — impact not confirmed
    • Multicluster Engine for Kubernetes
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • multicluster-engine/hypershift-addon-rhel9-operator:1786912006
    • multicluster-engine/hypershift-addon-rhel9-operator:1786548381
    • multicluster-engine/hypershift-addon-rhel9-operator:1787259113
    • multicluster-engine/hypershift-addon-rhel9-operator:1787264068

    3 more entries in the full advisory.

    Mitigation guidance
    • Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery