Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-70306: Microsoft Office SharePoint Spoofing Attack via Fake Pages

CVE-2026-70306 CVE-2026-70306
Summary

An attacker can create fake web pages in Microsoft Office SharePoint, tricking users into revealing sensitive information or performing malicious actions. This vulnerability affects Microsoft Office SharePoint, a widely used collaboration platform. To protect your organization, ensure you have the latest security updates installed and configure your SharePoint settings to prevent unauthorized access.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
microsoft microsoft sharepoint enterprise server 2016 < 16.0.5561.1001
microsoft microsoft sharepoint server 2019 < 16.0.10417.20175
microsoft microsoft sharepoint server subscription edition < 16.0.19725.20434
Original title
Microsoft Office SharePoint Spoofing Vulnerability
Original description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
mitre CVSS3.1 9.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 11 Aug 2026 · Updated: 11 Aug 2026 · First seen: 11 Aug 2026