CVE-2026-63516
Microsoft SharePoint Server Spoofing Vulnerability
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-63516 is a SharePoint vulnerability where a person with low-level access can send crafted network data to impersonate other users or services; this is a real, patch-needed risk for most businesses running affected SharePoint versions.
CVE-2026-63516 is a network-based spoofing issue (CWE-502) in Microsoft SharePoint Server where unsafe processing of serialized, externally supplied data can let an authorized attacker impersonate other identities over the network.
What to do now
- Check your Microsoft SharePoint Server version and edition (2016, 2019, or Subscription Edition) in your server’s installed build/version details.
- Compare your current version to the fixed versions listed in the Microsoft update guide.
- Upgrade SharePoint to the fixed build for your edition: 16.0.5565.1001 (SharePoint Enterprise Server 2016), 16.0.10417.20198 (SharePoint Server 2019), or 16.0.19725.20522 (SharePoint Server Subscription Edition and sharepoint server).
- After upgrading, re-check the SharePoint build number to confirm it matches the fixed version, then verify SharePoint authentication and permissions still behave as expected.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-63516 and every CVE in our database. Create a free account — no credit card required.
Create Free Account