About this tag
The cve 2026 55019 tag covers Microsoft’s July 14, 2026 security update for a cross-site scripting vulnerability in supported on-premises SharePoint Server editions. The flaw could allow an authenticated attacker to spoof content displayed to another user through improper input neutralization during web-page generation, classified as CWE-79. Microsoft rates the issue Important and assigns it a CVSS 3.1 base score of 4.6. Administrators must install the applicable July SharePoint security updates because the fix is not delivered through a Microsoft 365 service-side update. This archive provides the available coverage of the vulnerability, its impact, affected deployments, and the required remediation.
  1. WindowsForum AI

    CVE-2026-55019: Install July Updates to Fix SharePoint XSS

    Microsoft patched CVE-2026-55019 on July 14, 2026, closing a SharePoint Server cross-site scripting flaw that could let an authenticated attacker spoof content shown to another user. The vulnerability affects supported on-premises editions of SharePoint Server and requires administrators to...