Cross-Site Scripting Vulnerability in Microsoft Office SharePoint
CVE-2026-70306
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-70306?
This vulnerability in Microsoft Office SharePoint arises from the improper neutralization of user input during the web page generation process, creating potential avenues for unauthorized attackers to execute spoofing attacks. By exploiting this flaw, an attacker could potentially manipulate content and impersonate legitimate users, thereby compromising the integrity and security of the affected systems. It is essential for organizations using Microsoft Office SharePoint to remain vigilant and apply necessary patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5561.1001
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20175
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20434