CVE-2026-70306HighCVSS 9.3
Microsoft Office SharePoint Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002891 (Security Update) — fixed build 16.0.5561.1001 KB5002883 (Security Update) — fixed build 16.0.10417.20175 KB5002882 (Security Update) — fixed build 16.0.19725.20434
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70306
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=108723
- referencehttps://support.microsoft.com/help/5002891
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=108726
- referencehttps://support.microsoft.com/help/5002883
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=108730
- referencehttps://support.microsoft.com/help/5002882