You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
xss spoofing
About this tag
The xss spoofing tag covers cross-site scripting vulnerabilities that enable spoofing attacks in Microsoft enterprise products. Recent discussions focus on CVE-2026-45464, an Important-rated SharePoint Server spoofing flaw affecting Subscription Edition, 2019, and 2016, with security updates available. Another key topic is CVE-2025-62210, a high-severity XSS spoofing vulnerability in Dynamics 365 Field Service (online) rated CVSS 8.7, requiring urgent remediation. Both threads highlight how trusted enterprise portals and SaaS platforms can be exploited through XSS to spoof content, emphasizing the need for prompt patching and detection in on-premises and cloud environments.
Microsoft disclosed CVE-2026-45464 on June 9, 2026, as an Important-rated spoofing vulnerability in SharePoint Server caused by cross-site scripting, affecting SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, with security updates now...
Microsoft has published an advisory for CVE-2025-62210, a high-severity cross‑site scripting (XSS) / spoofing vulnerability affecting Dynamics 365 Field Service (online), and multiple independent trackers assigned a CVSS v3.1 base score of 8.7—a signal that organizations should treat this as an...