Junglewise Threat Intelligence

CVE-2026-55021: Microsoft SharePoint cross-site scripting vulnerability

CVE-2026-55021 · Severity: high · CVSS 7.3 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019. Vendors: Microsoft.

Executive brief

Microsoft SharePoint is a widely used collaboration and document management platform. A security vulnerability in this software could allow an attacker with basic user permissions to trick other users into performing unintended actions or revealing sensitive information. This type of attack, known as spoofing, can compromise the integrity of corporate data and lead to unauthorized access to internal resources.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation. An authenticated attacker with low-level privileges can exploit this flaw by sending a specially crafted request over the network. Successful exploitation requires user interaction, typically from a victim visiting a malicious or compromised page, and allows the attacker to perform spoofing and potentially gain unauthorized access to sensitive information. Microsoft has released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition to address this issue.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
  • Microsoft SharePoint Server 2019 < 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434

Timeline

  • 2026-07-14: disclosed: Initial publication of CVE-2026-55021
  • 2026-07-14: advisory: Microsoft released security update guide details

References

Related threats