CVE Tools

CVE-2026-70332

Microsoft Office SharePoint Spoofing Vulnerability

Published: Aug 6, 2026Updated: Aug 7, 2026 Sources: CVE List NVDCWE-79

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

In plain language

AI Act now

CVE-2026-70332 is a Microsoft SharePoint Online flaw that can let a remote attacker trick users with a fake page; because it’s tied to very serious security impact, you should review SharePoint Online protections and make sure you’re receiving Microsoft’s latest security fixes.

Executive summary

CVE-2026-70332 is a cross-site scripting (CWE-79) issue in Microsoft Office SharePoint that enables attacker-controlled web content to be rendered in a way that supports network-based spoofing; impact is severe because it can lead to user trust theft and session/user action compromise despite requiring user interaction.

If affected, business impact
User account/session compromisePhishing and credential theftService disruptionCompromised business workflows

What to do now

  1. Confirm your business uses Microsoft SharePoint Online (and not only on-prem SharePoint), and identify any users who can access it externally or receive share links.
  2. Check Microsoft’s update page for CVE-2026-70332 and note the recommended service/apply guidance for SharePoint Online; verify your tenant is current according to Microsoft’s instructions.
  3. Reduce exposure immediately: review external sharing settings, restrict who can create or share links, and disable or tightly control any untrusted third-party add-ins/custom scripts that could worsen spoofing risk.
  4. Train users who access SharePoint to treat unexpected SharePoint-looking prompts as suspicious and report them to IT; increase monitoring for unusual sign-ins or unexpected actions in SharePoint.
  5. Document completion and open a ticket with your Microsoft support channel (or IT vendor) referencing CVE-2026-70332 if Microsoft guidance indicates an action you must take at the tenant level.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

5

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-70332 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store