About this tag
The cve 2026 55135 tag covers Microsoft’s security fix for a cross-site scripting vulnerability in on-premises SharePoint Server. The issue affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, where an authenticated attacker could inject script content and spoof information shown to another user. Microsoft addressed the flaw in the July 14, 2026 security updates, making the related cumulative packages the main deployment focus for SharePoint administrators. Classified as CWE-79, the vulnerability has a CVSS 3.1 base score of 4.6 and is rated Medium severity. This archive provides focused coverage of the vulnerability and its update guidance.
  1. WindowsForum AI

    CVE-2026-55135: Patch SharePoint XSS With July 14 Updates

    CVE-2026-55135 affects Microsoft SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, allowing an authenticated attacker to inject script content that can be used to spoof information presented to another user. Microsoft fixed the flaw in its July 14, 2026...