{"schema_version":1,"title":"Microsoft Sharepoint-Server vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 30 vulnerabilities in Microsoft Sharepoint-Server: 0 in the last 7 days and 24 in the last 90 days, 7 of them critical and 7 exploited in the wild. The most recent, CVE-2026-69904, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/sharepoint-server","json_url":"https://junglewise.ai/threats/technologies/sharepoint-server.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/sharepoint-server","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":16,"all_time":30,"critical":7,"exploited":7,"last_7_days":0,"last_30_days":16,"last_90_days":24,"last_365_days":26},"latest":[{"cve":"CVE-2026-69904","cvss":3.5,"epss":0.0058,"slug":"cve-2026-69904-microsoft-office-sharepoint-server-side-request-forgery","title":"Microsoft Office SharePoint server-side request forgery","severity":"low","exploited":false,"published_at":"2026-09-08T18:20:00.75+00:00","url":"https://junglewise.ai/threats/cve-2026-69904-microsoft-office-sharepoint-server-side-request-forgery"},{"cve":"CVE-2026-69804","cvss":7.5,"epss":0.0051,"slug":"cve-2026-69804-microsoft-sharepoint-time-of-check-time-of-use-race-condition","title":"Microsoft SharePoint time-of-check time-of-use race condition","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:51.94+00:00","url":"https://junglewise.ai/threats/cve-2026-69804-microsoft-sharepoint-time-of-check-time-of-use-race-condition"},{"cve":"CVE-2026-69724","cvss":8.8,"epss":0.0078,"slug":"cve-2026-69724-microsoft-sharepoint-missing-authorization-in-code-execution","title":"Microsoft SharePoint missing authorization in code execution","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:44.593+00:00","url":"https://junglewise.ai/threats/cve-2026-69724-microsoft-sharepoint-missing-authorization-in-code-execution"},{"cve":"CVE-2026-69716","cvss":8.8,"epss":0.0099,"slug":"cve-2026-69716-microsoft-office-sharepoint-sql-injection","title":"Microsoft Office SharePoint SQL injection","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:43.703+00:00","url":"https://junglewise.ai/threats/cve-2026-69716-microsoft-office-sharepoint-sql-injection"},{"cve":"CVE-2026-69690","cvss":4.6,"epss":0.004,"slug":"cve-2026-69690-microsoft-office-sharepoint-cross-site-scripting-in-web-page","title":"Microsoft Office SharePoint cross-site scripting in web page generation","severity":"medium","exploited":false,"published_at":"2026-09-08T18:19:41.197+00:00","url":"https://junglewise.ai/threats/cve-2026-69690-microsoft-office-sharepoint-cross-site-scripting-in-web-page"},{"cve":"CVE-2026-69683","cvss":6.5,"epss":0.0084,"slug":"cve-2026-69683-microsoft-office-sharepoint-server-side-request-forgery","title":"Microsoft Office SharePoint server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-09-08T18:19:40.097+00:00","url":"https://junglewise.ai/threats/cve-2026-69683-microsoft-office-sharepoint-server-side-request-forgery"},{"cve":"CVE-2026-69636","cvss":6.5,"epss":0.01,"slug":"cve-2026-69636-microsoft-office-sharepoint-sql-injection","title":"Microsoft Office SharePoint SQL injection","severity":"medium","exploited":false,"published_at":"2026-09-08T18:19:35.867+00:00","url":"https://junglewise.ai/threats/cve-2026-69636-microsoft-office-sharepoint-sql-injection"},{"cve":"CVE-2026-69615","cvss":3.5,"epss":0.004,"slug":"cve-2026-69615-microsoft-office-sharepoint-cross-site-scripting-in-web-page","title":"Microsoft Office SharePoint cross-site scripting in web page generation","severity":"low","exploited":false,"published_at":"2026-09-08T18:19:33.17+00:00","url":"https://junglewise.ai/threats/cve-2026-69615-microsoft-office-sharepoint-cross-site-scripting-in-web-page"},{"cve":"CVE-2026-69465","cvss":8.8,"epss":0.0078,"slug":"cve-2026-69465-microsoft-office-sharepoint-missing-authorization-in-remote-code","title":"Microsoft Office SharePoint missing authorization in remote code execution","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:11.693+00:00","url":"https://junglewise.ai/threats/cve-2026-69465-microsoft-office-sharepoint-missing-authorization-in-remote-code"},{"cve":"CVE-2026-69464","cvss":8.8,"epss":0.0091,"slug":"cve-2026-69464-microsoft-office-sharepoint-privilege-escalation-via-unnecessary","title":"Microsoft Office SharePoint privilege escalation via unnecessary privileges","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:11.56+00:00","url":"https://junglewise.ai/threats/cve-2026-69464-microsoft-office-sharepoint-privilege-escalation-via-unnecessary"},{"cve":"CVE-2026-69417","cvss":7.3,"epss":0.0045,"slug":"cve-2026-69417-microsoft-office-sharepoint-cross-site-scripting-in-web-page","title":"Microsoft Office SharePoint cross-site scripting in web page generation","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:04.697+00:00","url":"https://junglewise.ai/threats/cve-2026-69417-microsoft-office-sharepoint-cross-site-scripting-in-web-page"},{"cve":"CVE-2026-69409","cvss":6.5,"epss":0.01,"slug":"cve-2026-69409-microsoft-office-sharepoint-execution-with-unnecessary-privileges","title":"Microsoft Office SharePoint execution with unnecessary privileges","severity":"medium","exploited":false,"published_at":"2026-09-08T18:19:03.733+00:00","url":"https://junglewise.ai/threats/cve-2026-69409-microsoft-office-sharepoint-execution-with-unnecessary-privileges"},{"cve":"CVE-2026-69402","cvss":7.3,"epss":0.0045,"slug":"cve-2026-69402-microsoft-office-sharepoint-cross-site-scripting","title":"Microsoft Office SharePoint cross-site scripting","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:02.543+00:00","url":"https://junglewise.ai/threats/cve-2026-69402-microsoft-office-sharepoint-cross-site-scripting"},{"cve":"CVE-2026-69282","cvss":8.8,"epss":0.0078,"slug":"cve-2026-69282-microsoft-office-sharepoint-improper-access-control","title":"Microsoft Office SharePoint improper access control","severity":"high","exploited":false,"published_at":"2026-09-08T18:18:42.693+00:00","url":"https://junglewise.ai/threats/cve-2026-69282-microsoft-office-sharepoint-improper-access-control"},{"cve":"CVE-2026-69273","cvss":8.8,"epss":0.0078,"slug":"cve-2026-69273-microsoft-office-sharepoint-improper-access-control-remote-code","title":"Microsoft Office SharePoint improper access control remote code execution","severity":"high","exploited":false,"published_at":"2026-09-08T18:18:40.297+00:00","url":"https://junglewise.ai/threats/cve-2026-69273-microsoft-office-sharepoint-improper-access-control-remote-code"},{"cve":"CVE-2026-69268","cvss":8.8,"epss":0.0078,"slug":"cve-2026-69268-microsoft-office-sharepoint-improper-access-control","title":"Microsoft Office SharePoint improper access control","severity":"high","exploited":false,"published_at":"2026-09-08T18:18:39.087+00:00","url":"https://junglewise.ai/threats/cve-2026-69268-microsoft-office-sharepoint-improper-access-control"},{"cve":"CVE-2026-55134","cvss":7.8,"slug":"cve-2026-55134-microsoft-office-word-stack-based-buffer-overflow","title":"Microsoft Office Word stack-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:20.163+00:00","url":"https://junglewise.ai/threats/cve-2026-55134-microsoft-office-word-stack-based-buffer-overflow"},{"cve":"CVE-2026-55128","cvss":7.8,"slug":"cve-2026-55128-microsoft-office-word-use-after-free-code-execution","title":"Microsoft Office Word use after free code execution","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:19.32+00:00","url":"https://junglewise.ai/threats/cve-2026-55128-microsoft-office-word-use-after-free-code-execution"},{"cve":"CVE-2026-55127","cvss":7.8,"slug":"cve-2026-55127-microsoft-office-word-heap-overflow-code-execution","title":"Microsoft Office Word heap overflow code execution","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:19.18+00:00","url":"https://junglewise.ai/threats/cve-2026-55127-microsoft-office-word-heap-overflow-code-execution"},{"cve":"CVE-2026-55124","cvss":5.5,"slug":"cve-2026-55124-microsoft-office-word-information-disclosure-via-improper-input","title":"Microsoft Office Word information disclosure via improper input validation","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:18.767+00:00","url":"https://junglewise.ai/threats/cve-2026-55124-microsoft-office-word-information-disclosure-via-improper-input"},{"cve":"CVE-2026-55055","cvss":7.8,"slug":"cve-2026-55055-microsoft-office-word-stack-based-buffer-overflow","title":"Microsoft Office Word stack-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:17.683+00:00","url":"https://junglewise.ai/threats/cve-2026-55055-microsoft-office-word-stack-based-buffer-overflow"},{"cve":"CVE-2026-55038","cvss":7.8,"slug":"cve-2026-55038-microsoft-office-word-stack-based-buffer-overflow","title":"Microsoft Office Word stack-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:15.083+00:00","url":"https://junglewise.ai/threats/cve-2026-55038-microsoft-office-word-stack-based-buffer-overflow"},{"cve":"CVE-2026-55033","cvss":7.8,"slug":"cve-2026-55033-microsoft-office-word-integer-overflow-code-execution","title":"Microsoft Office Word integer overflow code execution","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:14.293+00:00","url":"https://junglewise.ai/threats/cve-2026-55033-microsoft-office-word-integer-overflow-code-execution"},{"cve":"CVE-2026-56164","cvss":5.3,"slug":"cve-2026-56164-microsoft-sharepoint-missing-authentication-in-critical-function","title":"Microsoft SharePoint missing authentication in critical function","severity":"critical","exploited":true,"published_at":"2026-07-14T17:17:09.907+00:00","url":"https://junglewise.ai/threats/cve-2026-56164-microsoft-sharepoint-missing-authentication-in-critical-function"},{"cve":"CVE-2026-45659","cvss":8.8,"epss":0.0278,"slug":"cve-2026-45659-microsoft-office-sharepoint-deserialization-of-untrusted-data","title":"Microsoft Office SharePoint deserialization of untrusted data","severity":"critical","exploited":true,"published_at":"2026-05-22T23:16:56.273+00:00","url":"https://junglewise.ai/threats/cve-2026-45659-microsoft-office-sharepoint-deserialization-of-untrusted-data"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":1,"exploited":1,"vulnerabilities":8},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":16},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":963,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Microsoft Edge","slug":"edge-chromium-based","vulnerabilities":167,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"}],"technology":{"hub":true,"name":"Microsoft Sharepoint-Server","slug":"sharepoint-server","vendor":{"name":"Microsoft","slug":"microsoft","url":"https://junglewise.ai/threats/vendors/microsoft"},"aliases":[],"category":"web-server","homepage":"https://www.microsoft.com/en-us/microsoft-365/sharepoint/sharepoint-server","description":"A web-based collaboration and document management platform.","url":"https://junglewise.ai/threats/technologies/sharepoint-server"},"most_severe":[{"cve":"CVE-2025-53770","cvss":9.8,"epss":0.8818,"slug":"cve-2025-53770-microsoft-sharepoint-server-deserialization-of-untrusted-data","title":"Microsoft SharePoint Server deserialization of untrusted data","severity":"critical","exploited":true,"published_at":"2025-07-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-53770-microsoft-sharepoint-server-deserialization-of-untrusted-data"},{"cve":"CVE-2023-29357","cvss":9.8,"slug":"cve-2023-29357-microsoft-sharepoint-server-privilege-escalation-vulnerability","title":"Microsoft SharePoint Server Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2024-01-10T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-29357-microsoft-sharepoint-server-privilege-escalation-vulnerability"},{"cve":"CVE-2026-45659","cvss":8.8,"epss":0.0278,"slug":"cve-2026-45659-microsoft-office-sharepoint-deserialization-of-untrusted-data","title":"Microsoft Office SharePoint deserialization of untrusted data","severity":"critical","exploited":true,"published_at":"2026-05-22T23:16:56.273+00:00","url":"https://junglewise.ai/threats/cve-2026-45659-microsoft-office-sharepoint-deserialization-of-untrusted-data"},{"cve":"CVE-2017-11826","cvss":7.8,"slug":"cve-2017-11826-microsoft-office-remote-code-execution-vulnerability","title":"Microsoft Office Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-11826-microsoft-office-remote-code-execution-vulnerability"},{"cve":"CVE-2023-24955","cvss":7.2,"slug":"cve-2023-24955-microsoft-sharepoint-server-code-injection-vulnerability","title":"Microsoft SharePoint Server Code Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2024-03-26T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-24955-microsoft-sharepoint-server-code-injection-vulnerability"},{"cve":"CVE-2026-32201","cvss":6.5,"epss":0.0824,"slug":"cve-2026-32201-microsoft-sharepoint-server-improper-input-validation-spoofing","title":"Microsoft SharePoint Server improper input validation spoofing vulnerability","severity":"critical","exploited":true,"published_at":"2026-04-14T18:17:27.16+00:00","url":"https://junglewise.ai/threats/cve-2026-32201-microsoft-sharepoint-server-improper-input-validation-spoofing"},{"cve":"CVE-2026-56164","cvss":5.3,"slug":"cve-2026-56164-microsoft-sharepoint-missing-authentication-in-critical-function","title":"Microsoft SharePoint missing authentication in critical function","severity":"critical","exploited":true,"published_at":"2026-07-14T17:17:09.907+00:00","url":"https://junglewise.ai/threats/cve-2026-56164-microsoft-sharepoint-missing-authentication-in-critical-function"},{"cve":"CVE-2026-69716","cvss":8.8,"epss":0.0099,"slug":"cve-2026-69716-microsoft-office-sharepoint-sql-injection","title":"Microsoft Office SharePoint SQL injection","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:43.703+00:00","url":"https://junglewise.ai/threats/cve-2026-69716-microsoft-office-sharepoint-sql-injection"},{"cve":"CVE-2026-69464","cvss":8.8,"epss":0.0091,"slug":"cve-2026-69464-microsoft-office-sharepoint-privilege-escalation-via-unnecessary","title":"Microsoft Office SharePoint privilege escalation via unnecessary privileges","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:11.56+00:00","url":"https://junglewise.ai/threats/cve-2026-69464-microsoft-office-sharepoint-privilege-escalation-via-unnecessary"},{"cve":"CVE-2026-69724","cvss":8.8,"epss":0.0078,"slug":"cve-2026-69724-microsoft-sharepoint-missing-authorization-in-code-execution","title":"Microsoft SharePoint missing authorization in code execution","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:44.593+00:00","url":"https://junglewise.ai/threats/cve-2026-69724-microsoft-sharepoint-missing-authorization-in-code-execution"}],"generated_at":"2026-09-26T09:24:00.138874+00:00"}