CVE-2026-64902
Microsoft SharePoint Server Spoofing Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-64902 is a SharePoint flaw that lets a logged-in user inject malicious script into SharePoint pages, potentially tricking other people who view those pages; if you only have trusted accounts and no one is already compromised, the risk is lower, but it’s still worth patching.
CVE-2026-64902 is a spoofing-style web vulnerability (cross-site scripting, CWE-79) in Microsoft SharePoint Server products where an authorized user can inject script through a trusted interface so other users’ browsers execute it in their session.
What to do now
- Check whether your Microsoft SharePoint Server (2016, 2019, or Subscription Edition) is installed and identify its current version.
- Confirm whether any non-admin or external users have access to create/edit content that can be rendered as web pages in SharePoint.
- If you use SharePoint with multiple contributors, assume the risk of malicious or compromised accounts and plan to patch.
- Upgrade SharePoint to the fixed versions: SharePoint Server 2016 → 16.0.5565.1001; SharePoint Server 2019 → 16.0.10417.20198; SharePoint Server Subscription Edition → 16.0.19725.20522.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-64902 and every CVE in our database. Create a free account — no credit card required.
Create Free Account