Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Microsoft SharePoint Enterprise Server 2016.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-62917MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityImproper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-20Aug 11, 2026 | CVSS4.6v3.1 | EPSS0.356% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62839MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityInsufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-522Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.577% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58639MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityServer-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-918Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.769% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-70306CRITICAL | Microsoft Office SharePoint Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. CWE-79Aug 11, 2026 | CVSS9.3v3.1 | EPSS0.561% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66808HIGH | Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CWE-502Aug 11, 2026 | CVSS8.8v3.1 | EPSS1.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66805HIGH | Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CWE-502Aug 11, 2026 | CVSS8.8v3.1 | EPSS1.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64921HIGH | Microsoft SharePoint Server Elevation of Privilege VulnerabilityMissing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CWE-306Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.825% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64916MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-79Aug 11, 2026 | CVSS4.6v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64901HIGH | Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CWE-502Aug 11, 2026 | CVSS8.8v3.1 | EPSS1.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64902MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-79Aug 11, 2026 | CVSS4.6v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64900HIGH | Microsoft SharePoint Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-79Aug 11, 2026 | CVSS7.3v3.1 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64897MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-79Aug 11, 2026 | CVSS4.6v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-70324HIGH | Microsoft SharePoint Elevation of Privilege VulnerabilityServer-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CWE-918Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.589% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65660MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-94Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.683% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65663HIGH | Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CWE-502Aug 11, 2026 | CVSS8.8v3.1 | EPSS1.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65658HIGH | Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CWE-502Aug 11, 2026 | CVSS8.8v3.1 | EPSS1.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64922MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-79Aug 11, 2026 | CVSS4.6v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-63520HIGH | Microsoft SharePoint Server Remote Code Execution VulnerabilityImproper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CWE-20Aug 11, 2026 | CVSS8.1v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-63516MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-502Aug 11, 2026 | CVSS6.5v3.1 | EPSS1.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-63512MEDIUM | Microsoft SharePoint Server Tampering VulnerabilityIncorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. CWE-863Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.484% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-63514HIGH | Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CWE-502Aug 11, 2026 | CVSS8.8v3.1 | EPSS1.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62837MEDIUM | Microsoft SharePoint Server Information Disclosure VulnerabilityRelative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. CWE-23Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.794% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62827HIGH | Microsoft SharePoint Server Elevation of Privilege VulnerabilityImproper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CWE-287Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.604% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62826MEDIUM | Microsoft SharePoint Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-79Jul 16, 2026 | CVSS4.6v3.1 | EPSS0.331% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55121MEDIUM | Microsoft Office Information Disclosure VulnerabilityOut-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. CWE-125Jul 14, 2026 | CVSS5.5v3.1 | EPSS0.362% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |