CVE-2026-70332: Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Other sources
Microsoft Office SharePoint Spoofing Vulnerability
— Microsoft
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70332?
CVE-2026-70332 has a critical severity rating of 9.6.
How do I fix CVE-2026-70332?
To mitigate CVE-2026-70332, ensure that all Microsoft Office SharePoint instances are updated to the latest patches provided by Microsoft.
What type of attack does CVE-2026-70332 allow?
CVE-2026-70332 allows unauthorized attackers to perform spoofing attacks over a network.
Which software is affected by CVE-2026-70332?
CVE-2026-70332 affects Microsoft Office and Microsoft SharePoint Online.
What kind of vulnerability is CVE-2026-70332 classified as?
CVE-2026-70332 is classified as a cross-site scripting (XSS) vulnerability.