CVE-2026-64900
Microsoft SharePoint Server Spoofing Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-64900 is a SharePoint flaw where a logged-in user can plant malicious code in SharePoint pages so that other visitors’ browsers execute it, and typical small businesses should patch if they have affected SharePoint versions with users who can create or edit content.
In Microsoft SharePoint Enterprise Server 2016/2019/Subscription Edition (sharepoint server), an authenticated user with low privileges can inject malicious script into generated web pages (insufficient sanitization of user-generated content), enabling cross-site scripting–style session impact when victims browse the crafted page.
What to do now
- Check whether you run one of these Microsoft SharePoint versions: SharePoint Enterprise Server 2016, SharePoint Server 2019, or SharePoint Server Subscription Edition (or confirm your “sharepoint server” build number).
- Compare your current SharePoint build to the fixed builds: Enterprise Server 2016 → 16.0.5565.1001; SharePoint Server 2019 → 16.0.10417.20198; Subscription Edition → 16.0.19725.20522.
- Upgrade/apply the Microsoft patch for CVE-2026-64900 from the Microsoft Update Guide page linked below.
- If you can’t patch immediately, restrict who can create/edit SharePoint pages and reduce exposure by limiting where external or low-privilege users can input content that produces web pages.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-64900 and every CVE in our database. Create a free account — no credit card required.
Create Free Account