Technology · Microsoft
Microsoft SharePoint Enterprise Server 2016 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 34 vulnerabilities in Microsoft SharePoint Enterprise Server 2016: 0 in the last 7 days and 32 in the last 90 days, 6 of them critical and 6 exploited in the wild. The most recent, CVE-2026-62826, was published on 16 July 2026.
- Last 7 days
- 0
- Last 90 days
- 32
- Critical, all time
- 6
- Exploited in the wild
- 6
About Microsoft SharePoint Enterprise Server 2016
A collaboration and document management platform for enterprise environments.
Latest Microsoft SharePoint Enterprise Server 2016 vulnerabilities
- CVE-2026-62826: Microsoft SharePoint cross-site scripting vulnerabilitymediumCVSS 4.6
- CVE-2026-58277: Microsoft SharePoint improper authorization privilege escalationhighCVSS 8.8
- CVE-2026-56192: Microsoft Office Out-of-bounds Read Information DisclosuremediumCVSS 5.5
- CVE-2026-56157: Microsoft SharePoint improper access control spoofing vulnerabilitymediumCVSS 5.4
- CVE-2026-55142: Microsoft Office Word numeric truncation information disclosuremediumCVSS 5.5
- CVE-2026-55135: Microsoft Office SharePoint cross-site scriptingmediumCVSS 4.6
- CVE-2026-55132: Microsoft Office Word double free local code executionhighCVSS 7.8
- CVE-2026-55130: Microsoft Office Word heap buffer overflowhighCVSS 7.8
- CVE-2026-55126: Microsoft SharePoint cross-site scripting vulnerabilityhighCVSS 7.3
- CVE-2026-55125: Microsoft Office heap overflow in code executionhighCVSS 7.8
- CVE-2026-55121: Microsoft Office out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55052: Microsoft SharePoint privilege escalation via missing authorizationhighCVSS 8.8
- CVE-2026-55051: Microsoft SharePoint SSRF information disclosuremediumCVSS 6.5
- CVE-2026-55050: Microsoft Office Word out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55047: Microsoft Office Out-of-bounds Read Information DisclosuremediumCVSS 5.5
- CVE-2026-55045: Microsoft Office out-of-bounds read code executionhighCVSS 8.4
- CVE-2026-55040: Microsoft SharePoint weak authentication security feature bypasscriticalexploited in the wildCVSS 9.1EPSS 17.5%
- CVE-2026-55035: Microsoft Office out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55034: Microsoft SharePoint cross-site scripting in web page generationhighCVSS 7.3
- CVE-2026-55030: Microsoft SharePoint cross-site scripting vulnerabilitymediumCVSS 4.6
- CVE-2026-55028: Microsoft Office out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55027: Microsoft Office out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55026: Microsoft Office integer overflow information disclosuremediumCVSS 6.2
- CVE-2026-55023: Microsoft Office out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55021: Microsoft SharePoint cross-site scripting vulnerabilityhighCVSS 7.3
Most severe Microsoft SharePoint Enterprise Server 2016 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-50522: Microsoft SharePoint remote code execution via unsafe deserializationcriticalexploited in the wildCVSS 9.8EPSS 20.3%
- CVE-2026-58644: Microsoft SharePoint remote code execution via untrusted deserializationcriticalexploited in the wildCVSS 9.8EPSS 1.3%
- CVE-2026-55040: Microsoft SharePoint weak authentication security feature bypasscriticalexploited in the wildCVSS 9.1EPSS 17.5%
- CVE-2026-45659: Microsoft Office SharePoint deserialization of untrusted datacriticalexploited in the wildCVSS 8.8EPSS 2.8%
- CVE-2025-49706: Microsoft SharePoint improper authentication vulnerabilitycriticalexploited in the wildCVSS 6.5EPSS 75.0%
- CVE-2026-56164: Microsoft SharePoint missing authentication in critical functioncriticalexploited in the wildCVSS 5.3
- CVE-2026-58277: Microsoft SharePoint improper authorization privilege escalationhighCVSS 8.8
- CVE-2026-55052: Microsoft SharePoint privilege escalation via missing authorizationhighCVSS 8.8
- CVE-2026-55045: Microsoft Office out-of-bounds read code executionhighCVSS 8.4
- CVE-2026-55132: Microsoft Office Word double free local code executionhighCVSS 7.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 32 | 4 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/sharepoint-enterprise-server-2016.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft SharePoint Enterprise Server 2016 vulnerabilities", https://junglewise.ai/threats/technologies/sharepoint-enterprise-server-2016, 26 September 2026.