You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026 26105
About this tag
CVE-2026-26105 is a high-severity spoofing vulnerability in on-premises Microsoft SharePoint Server, disclosed and patched in the March 2026 security update. The flaw, classified as cross-site scripting (CWE-79), allows an unauthenticated remote attacker to inject malicious content that can spoof trusted site elements. This could enable phishing attacks, credential theft, session hijacking, or content manipulation. Microsoft assigned a CVSS v3.1 base score of 8.1 (High) and released fixes for affected SharePoint Server builds. Administrators of on-premises SharePoint deployments should prioritize applying this patch to mitigate the risk of exploitation.
Microsoft released an important security update on March 10, 2026, to address CVE-2026-26105 — a high‑severity spoofing (cross‑site scripting, CWE‑79) vulnerability affecting on‑premises Microsoft SharePoint Server. The flaw allows an unauthenticated remote actor to deliver specially crafted...