CVE-2026-64922
Microsoft SharePoint Server Spoofing Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-64922 is a SharePoint bug where a low-level logged-in user can alter a webpage to trick others into clicking or loading malicious content; it’s a real risk if your SharePoint is reachable and users can add or influence page content.
CVE-2026-64922 is an authenticated webpage spoofing issue in Microsoft SharePoint Server (CWE-79) where a low-privileged user can inject script/content to trick other users interacting with SharePoint pages, causing limited information leakage and minor record/data integrity changes.
What to do now
- Check which SharePoint Server product and build you run (2016, 2019, Subscription Edition, or other) and note your current version.
- Compare your current version to the fixed versions for CVE-2026-64922: 2016 fixed in 16.0.5565.1001; 2019 fixed in 16.0.10417.20198; Subscription Edition fixed in 16.0.19725.20522.
- Apply the official Microsoft update for CVE-2026-64922 from the MSRC update guide as soon as possible.
- After updating, review SharePoint page/admin activity around the time of the change and verify no unexpected page/script content was added.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-64922 and every CVE in our database. Create a free account — no credit card required.
Create Free Account