SB2026071735 - Multiple vulnerabilities in Microsoft SharePoint Server



SB2026071735 - Multiple vulnerabilities in Microsoft SharePoint Server

Published: July 17, 2026

Security Bulletin ID SB2026071735
CSH Severity
High
Patch available
YES
Number of vulnerabilities 16
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 13% Medium 13% Low 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 16 vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2026-55021)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to cross-site scripting in Microsoft Office SharePoint when generating web pages. A remote user can send a malicious link to a user and convince the user to open it to perform spoofing.

User interaction is required.


2) Cross-site scripting (CVE-ID: CVE-2026-55020)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint when handling malicious links in web pages. A remote user can send a malicious link to a user to perform spoofing.

User interaction is required to open the malicious link.


3) Cross-site scripting (CVE-ID: CVE-2026-55019)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when handling a malicious link. A remote user can send a specially crafted link and convince the user to open it to perform spoofing.

Successful exploitation could allow limited disclosure of sensitive information and limited modification of disclosed information. User interaction is required to open a crafted link.


4) Cross-site scripting (CVE-ID: CVE-2026-55016)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint when handling malicious web content over the network. A remote user can send a malicious link and convince the user to open it to perform spoofing.

User interaction is required to open a malicious link.


5) Weak Authentication (CVE-ID: CVE-2026-55040)

CWE-ID: CWE-1390 - Weak Authentication

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to bypass an authentication security feature.

The vulnerability exists due to weak authentication in Microsoft Office SharePoint when handling network requests. A remote attacker can make an anonymous connection to bypass an authentication security feature.

Successful exploitation can allow impersonation, disclosure of files, and modification of data.


6) Cross-site scripting (CVE-ID: CVE-2026-55030)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information and modify disclosed information.

The vulnerability exists due to cross-site scripting in Microsoft SharePoint Server when generating web pages. A remote user can send a malicious link and convince the user to open it to disclose sensitive information and modify disclosed information.

User interaction is required to open a malicious link.


7) Cross-site scripting (CVE-ID: CVE-2026-55034)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint when handling web page generation. A remote user can send a malicious link to a user to perform spoofing.

User interaction is required to open the malicious link.


8) Cross-site scripting (CVE-ID: CVE-2026-55126)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when handling a malicious link. A remote user can send a specially crafted link to perform spoofing.

User interaction is required to open the malicious link.


9) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-55051)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to server-side request forgery (ssrf) in Microsoft Office SharePoint when handling network requests. A remote user can send a specially crafted request to disclose sensitive information.

An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.


10) Missing Authorization (CVE-ID: CVE-2026-55052)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to missing authorization in Microsoft Office SharePoint when handling network requests. A remote user can send crafted requests to escalate privileges.

The attacker gains the rights of the user running the affected application.


11) Cross-site scripting (CVE-ID: CVE-2026-55135)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to cross-site scripting in Microsoft Office SharePoint when generating web pages. A remote user can send a malicious link to a user and convince the user to open it to perform spoofing.

User interaction is required.


12) Improper access control (CVE-ID: CVE-2026-56157)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to spoof trusted content.

The vulnerability exists due to improper access control in Microsoft Office SharePoint when handling network requests. A remote user can send crafted requests to spoof trusted content.

The issue can lead to some loss of confidentiality and integrity, but no loss of availability.


13) Improper Authorization (CVE-ID: CVE-2026-58277)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to elevate privileges.

The vulnerability exists due to improper authorization in Microsoft Office SharePoint when handling network requests. A remote user can send crafted requests to elevate privileges.

A successful exploit grants the rights of the user running the affected application.


14) External Control of File Name or Path (CVE-ID: CVE-2026-54108)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to external control of file name or path in Microsoft Office SharePoint when handling network requests. A remote user can manipulate a file name or path to disclose sensitive information.


15) Deserialization of Untrusted Data (CVE-ID: CVE-2026-50522)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in Microsoft Office SharePoint when handling network requests. A remote attacker can send crafted serialized data to execute arbitrary code.


16) Cross-site scripting (CVE-ID: CVE-2026-62826)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information and modify data.

The vulnerability exists due to cross-site scripting in Microsoft Office SharePoint when generating web pages with unneutralized input. A remote user can send a malicious link to a user and convince the user to open it to disclose sensitive information and modify data.

User interaction is required for exploitation.


Remediation

Install update from vendor's website.