CVE-2026-64902
Office: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2026-64902)
mediumEPSS 0.6%
Affected
- Microsoft/Access
2016..* - Microsoft/Azure
SQL Managed Instance..* - Microsoft/Excel
2016..* - Microsoft/Office
2016..* - Microsoft/Office
LTSC for Mac 2021..* - Microsoft/Office
LTSC 2021..* - Microsoft/Office
LTSC for Mac 2024..* - Microsoft/Office
LTSC 2024..* - Microsoft/Office
2019..* - Microsoft/Office 365
for Mac..* - Microsoft/OneDrive
for MacOS..* - Microsoft/Outlook
2016..* - Microsoft/PowerPoint
2016..* - Microsoft/Service Bus
Azure Service Bus..* - Microsoft/SharePoint
Enterprise Server 2016..* - Microsoft/SharePoint
Server Subscription Edition..* - Microsoft/SharePoint
Online..* - Microsoft/Teams
for iOS..* - Microsoft/Teams
for Android..* - Microsoft/Word
2016..*
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
MicrosoftAccess
2016MicrosoftAzure
SQL Managed InstanceMicrosoftExcel
2016MicrosoftOffice
20162019LTSC 2021LTSC 2024LTSC for Mac 2021LTSC for Mac 2024MicrosoftOffice 365
for MacMicrosoftOneDrive
for MacOSMicrosoftOutlook
2016MicrosoftPowerPoint
2016MicrosoftService Bus
Azure Service BusMicrosoftSharePoint
Enterprise Server 2016OnlineServer Subscription EditionMicrosoftTeams
for Androidfor iOSMicrosoftWord
2016Metrics
Show all metrics
Severity
medium
65.09
no public PoC known
4.6
Published
2026-08-11 17:06 UTC
CWE-79
Weakness classes (CWE)
CWE-79Base
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-11 20:54 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- CPE Configuration: OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.19725.20522
- Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64902 Types: Patch, Vendor Advisory
- CVE Modified2026-08-11 19:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-64902","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
- Affected: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
- Description: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVSS V3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- CWE: CWE-79