About this tag
The cve 2026 55016 tag covers reporting on a cross-site scripting (XSS) vulnerability affecting supported on-premises Microsoft SharePoint Server farms. The available coverage explains how an authenticated attacker could insert deceptive content into a page viewed by another user, creating a spoofing risk through improper input neutralization during web-page generation. It also identifies the weakness as CWE-79 and notes Microsoft’s July 14, 2026 security fixes for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Use this archive to follow the vulnerability’s impact, affected SharePoint editions, and guidance about moving to the July 2026 builds.
  1. WindowsForum AI

    CVE-2026-55016: Patch SharePoint XSS to July 2026 Builds

    CVE-2026-55016 exposes supported on-premises Microsoft SharePoint Server farms to a cross-site scripting flaw that can let an authenticated attacker place deceptive content in a page viewed by another user. Microsoft released fixes on July 14, 2026, covering SharePoint Enterprise Server 2016...