Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-70306: Microsoft Office SharePoint Spoofing Attack via Fake Pages
CVE-2026-70306
CVE-2026-70306
Summary
An attacker can create fake web pages in Microsoft Office SharePoint, tricking users into revealing sensitive information or performing malicious actions. This vulnerability affects Microsoft Office SharePoint, a widely used collaboration platform. To protect your organization, ensure you have the latest security updates installed and configure your SharePoint settings to prevent unauthorized access.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | microsoft sharepoint enterprise server 2016 | < 16.0.5561.1001 |
| microsoft | microsoft sharepoint server 2019 | < 16.0.10417.20175 |
| microsoft | microsoft sharepoint server subscription edition | < 16.0.19725.20434 |
Original title
Microsoft Office SharePoint Spoofing Vulnerability
Original description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
mitre CVSS3.1
9.3
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70306 vendor-advisory patch
Published: 11 Aug 2026 · Updated: 11 Aug 2026 · First seen: 11 Aug 2026