CVE-2026-64916
Microsoft SharePoint Server Spoofing Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-64916 is a SharePoint flaw where a logged-in user can inject malicious webpage scripts to impersonate the site and trick other users; if you don’t have SharePoint users with untrusted accounts, the risk is lower, but you should still update because patching is available.
Authenticated cross-site scripting (CWE-79) in Microsoft SharePoint allows an attacker with low privileges to inject script into generated web pages over the network, enabling spoofing/impersonation of the SharePoint interface to trick users.
What to do now
- Check your Microsoft SharePoint Server version (2016/2019/Subscription Edition) and see whether it is older than the fixed version listed in the Microsoft update guide for CVE-2026-64916.
- If you’re using SharePoint Enterprise Server 2016, upgrade to 16.0.5565.1001 or later.
- If you’re using SharePoint Server 2019, upgrade to 16.0.10417.20198 or later.
- If you’re using SharePoint Server Subscription Edition (or “sharepoint server”), upgrade to 16.0.19725.20522 or later.
- After upgrading, review SharePoint sign-in and web activity logs for suspicious behavior from any non-admin accounts, and remove/disable any accounts that shouldn’t have access.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-64916 and every CVE in our database. Create a free account — no credit card required.
Create Free Account