CVE-2026-70332
Microsoft Office SharePoint Spoofing Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-70332 is a Microsoft SharePoint Online flaw that can let a remote attacker trick users with a fake page; because it’s tied to very serious security impact, you should review SharePoint Online protections and make sure you’re receiving Microsoft’s latest security fixes.
CVE-2026-70332 is a cross-site scripting (CWE-79) issue in Microsoft Office SharePoint that enables attacker-controlled web content to be rendered in a way that supports network-based spoofing; impact is severe because it can lead to user trust theft and session/user action compromise despite requiring user interaction.
What to do now
- Confirm your business uses Microsoft SharePoint Online (and not only on-prem SharePoint), and identify any users who can access it externally or receive share links.
- Check Microsoft’s update page for CVE-2026-70332 and note the recommended service/apply guidance for SharePoint Online; verify your tenant is current according to Microsoft’s instructions.
- Reduce exposure immediately: review external sharing settings, restrict who can create or share links, and disable or tightly control any untrusted third-party add-ins/custom scripts that could worsen spoofing risk.
- Train users who access SharePoint to treat unexpected SharePoint-looking prompts as suspicious and report them to IT; increase monitoring for unusual sign-ins or unexpected actions in SharePoint.
- Document completion and open a ticket with your Microsoft support channel (or IT vendor) referencing CVE-2026-70332 if Microsoft guidance indicates an action you must take at the tenant level.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft's Patch Tuesday Deluge Continues With August Updatesen·Dark Reading· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-70332 and every CVE in our database. Create a free account — no credit card required.
Create Free Account