SB2026071735 - Multiple vulnerabilities in Microsoft SharePoint Server
Published: July 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 16 vulnerabilities.
1) Cross-site scripting (CVE-ID: CVE-2026-55021)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to cross-site scripting in Microsoft Office SharePoint when generating web pages. A remote user can send a malicious link to a user and convince the user to open it to perform spoofing.
User interaction is required.
2) Cross-site scripting (CVE-ID: CVE-2026-55020)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint when handling malicious links in web pages. A remote user can send a malicious link to a user to perform spoofing.
User interaction is required to open the malicious link.
3) Cross-site scripting (CVE-ID: CVE-2026-55019)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when handling a malicious link. A remote user can send a specially crafted link and convince the user to open it to perform spoofing.
Successful exploitation could allow limited disclosure of sensitive information and limited modification of disclosed information. User interaction is required to open a crafted link.
4) Cross-site scripting (CVE-ID: CVE-2026-55016)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint when handling malicious web content over the network. A remote user can send a malicious link and convince the user to open it to perform spoofing.
User interaction is required to open a malicious link.
5) Weak Authentication (CVE-ID: CVE-2026-55040)
CWE-ID: CWE-1390 - Weak Authentication
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to bypass an authentication security feature.
The vulnerability exists due to weak authentication in Microsoft Office SharePoint when handling network requests. A remote attacker can make an anonymous connection to bypass an authentication security feature.
Successful exploitation can allow impersonation, disclosure of files, and modification of data.
6) Cross-site scripting (CVE-ID: CVE-2026-55030)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information and modify disclosed information.
The vulnerability exists due to cross-site scripting in Microsoft SharePoint Server when generating web pages. A remote user can send a malicious link and convince the user to open it to disclose sensitive information and modify disclosed information.
User interaction is required to open a malicious link.
7) Cross-site scripting (CVE-ID: CVE-2026-55034)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint when handling web page generation. A remote user can send a malicious link to a user to perform spoofing.
User interaction is required to open the malicious link.
8) Cross-site scripting (CVE-ID: CVE-2026-55126)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when handling a malicious link. A remote user can send a specially crafted link to perform spoofing.
User interaction is required to open the malicious link.
9) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-55051)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to server-side request forgery (ssrf) in Microsoft Office SharePoint when handling network requests. A remote user can send a specially crafted request to disclose sensitive information.
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
10) Missing Authorization (CVE-ID: CVE-2026-55052)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to missing authorization in Microsoft Office SharePoint when handling network requests. A remote user can send crafted requests to escalate privileges.
The attacker gains the rights of the user running the affected application.
11) Cross-site scripting (CVE-ID: CVE-2026-55135)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to cross-site scripting in Microsoft Office SharePoint when generating web pages. A remote user can send a malicious link to a user and convince the user to open it to perform spoofing.
User interaction is required.
12) Improper access control (CVE-ID: CVE-2026-56157)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to spoof trusted content.
The vulnerability exists due to improper access control in Microsoft Office SharePoint when handling network requests. A remote user can send crafted requests to spoof trusted content.
The issue can lead to some loss of confidentiality and integrity, but no loss of availability.
13) Improper Authorization (CVE-ID: CVE-2026-58277)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to improper authorization in Microsoft Office SharePoint when handling network requests. A remote user can send crafted requests to elevate privileges.
A successful exploit grants the rights of the user running the affected application.
14) External Control of File Name or Path (CVE-ID: CVE-2026-54108)
CWE-ID: CWE-73 - External Control of File Name or Path
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to external control of file name or path in Microsoft Office SharePoint when handling network requests. A remote user can manipulate a file name or path to disclose sensitive information.
15) Deserialization of Untrusted Data (CVE-ID: CVE-2026-50522)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in Microsoft Office SharePoint when handling network requests. A remote attacker can send crafted serialized data to execute arbitrary code.
16) Cross-site scripting (CVE-ID: CVE-2026-62826)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to cross-site scripting in Microsoft Office SharePoint when generating web pages with unneutralized input. A remote user can send a malicious link to a user and convince the user to open it to disclose sensitive information and modify data.
User interaction is required for exploitation.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55021
- https://support.microsoft.com/help/5002891
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55020
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55019
- https://support.microsoft.com/help/5002882
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55016
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55040
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55030
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55034
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55126
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55051
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55052
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-55135
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-56157
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-58277
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-54108
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-50522
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62826