CVE-2026-64902

Office: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2026-64902)

mediumEPSS 0.6%

Affected

  • Microsoft/Access 2016..*
  • Microsoft/Azure SQL Managed Instance..*
  • Microsoft/Excel 2016..*
  • Microsoft/Office 2016..*
  • Microsoft/Office LTSC for Mac 2021..*
  • Microsoft/Office LTSC 2021..*
  • Microsoft/Office LTSC for Mac 2024..*
  • Microsoft/Office LTSC 2024..*
  • Microsoft/Office 2019..*
  • Microsoft/Office 365 for Mac..*
  • Microsoft/OneDrive for MacOS..*
  • Microsoft/Outlook 2016..*
  • Microsoft/PowerPoint 2016..*
  • Microsoft/Service Bus Azure Service Bus..*
  • Microsoft/SharePoint Enterprise Server 2016..*
  • Microsoft/SharePoint Server Subscription Edition..*
  • Microsoft/SharePoint Online..*
  • Microsoft/Teams for iOS..*
  • Microsoft/Teams for Android..*
  • Microsoft/Word 2016..*

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

MicrosoftAccess
2016
MicrosoftAzure
SQL Managed Instance
MicrosoftExcel
2016
MicrosoftOffice
20162019LTSC 2021LTSC 2024LTSC for Mac 2021LTSC for Mac 2024
MicrosoftOffice 365
for Mac
MicrosoftOneDrive
for MacOS
MicrosoftOutlook
2016
MicrosoftPowerPoint
2016
MicrosoftService Bus
Azure Service Bus
MicrosoftSharePoint
Enterprise Server 2016OnlineServer Subscription Edition
MicrosoftTeams
for Androidfor iOS
MicrosoftWord
2016

Metrics

5.4
Source: nvd-v3
46.2 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
medium
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-11 17:06 UTC
CWE-79

Weakness classes (CWE)

  • CWE-79Base

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-08-11 20:54 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
    • CPE Configuration: OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.19725.20522
    • Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64902 Types: Patch, Vendor Advisory
  2. CVE Modified2026-08-11 19:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-64902","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
    • Affected: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
    • Description: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
    • CWE: CWE-79

Linked advisories