Microsoft SharePoint Spoofing Vulnerability via Cross-Site Scripting

Vulnerability

A cross-site scripting vulnerability has been identified in Microsoft Office SharePoint, allowing an authorized attacker to perform spoofing over the network. This issue arises from improper neutralization of input during web page generation.

Impact

Exploitation of this vulnerability could lead to spoofing attacks, allowing an attacker to impersonate another user or entity.

Remediation

Users should install the security update released in July 2026. For SharePoint Server 2016 users, the same update applies to SharePoint Enterprise Server 2016.

Added: Jul 16, 2026, 10:36 PM
Updated: Jul 16, 2026, 10:36 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
1.7
exploitability
5.8
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.