Microsoft SharePoint Server

38 known vulnerabilities in Microsoft SharePoint Server, 8 critical, 16 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-65660 CVSS 8.8 high · actively exploited Microsoft SharePoint Code Injection Vulnerability
  • CVE-2026-55040 CVSS 9.1 critical · actively exploited Microsoft SharePoint Weak Authentication Vulnerability
  • CVE-2026-58644 CVSS 9.8 critical · actively exploited Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • CVE-2026-56164 CVSS 9.8 critical · actively exploited Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
  • CVE-2026-50522 CVSS 9.8 critical · actively exploited Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • CVE-2026-45659 CVSS 8.8 high · actively exploited Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
  • CVE-2026-32201 CVSS 6.5 medium · actively exploited Microsoft SharePoint Server Improper Input Validation Vulnerability
  • CVE-2026-20963 CVSS 9.8 critical · actively exploited Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • CVE-2025-53770 CVSS 9.8 critical · actively exploited Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • CVE-2025-49706 CVSS 6.5 medium · actively exploited Microsoft SharePoint Improper Authentication Vulnerability

Latest vulnerabilities

  • CVE-2026-69904 CVSS 3.5 low Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
  • CVE-2026-69804 CVSS 7.5 high Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a…
  • CVE-2026-69724 CVSS 8.8 high Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
  • CVE-2026-69716 CVSS 8.8 high Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized…
  • CVE-2026-69690 CVSS 5.4 medium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized…
  • CVE-2026-69683 CVSS 7.7 high Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
  • CVE-2026-69636 CVSS 6.5 medium Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized…
  • CVE-2026-69615 CVSS 4.8 medium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized…
  • CVE-2026-69465 CVSS 8.8 high Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
  • CVE-2026-69464 CVSS 8.8 high Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
  • CVE-2026-69417 CVSS 5.4 medium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized…
  • CVE-2026-69409 CVSS 6.5 medium Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
  • CVE-2026-69402 CVSS 5.4 medium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized…
  • CVE-2026-69282 CVSS 8.8 high Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
  • CVE-2026-69273 CVSS 8.8 high Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
  • CVE-2026-69268 CVSS 8.8 high Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
  • CVE-2026-65660 CVSS 8.8 high · actively exploited Microsoft SharePoint Code Injection Vulnerability
  • CVE-2026-63520 CVSS 8.1 high Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
  • CVE-2026-55040 CVSS 9.1 critical · actively exploited Microsoft SharePoint Weak Authentication Vulnerability
  • CVE-2026-58644 CVSS 9.8 critical · actively exploited Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • CVE-2026-56164 CVSS 9.8 critical · actively exploited Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
  • CVE-2026-50522 CVSS 9.8 critical · actively exploited Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • CVE-2026-45659 CVSS 8.8 high · actively exploited Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
  • CVE-2026-32201 CVSS 6.5 medium · actively exploited Microsoft SharePoint Server Improper Input Validation Vulnerability
  • CVE-2026-26114 CVSS 8.8 high Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
  • CVE-2026-26113 CVSS 7.8 high Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
  • CVE-2026-26106 CVSS 8.8 high Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
  • CVE-2026-20963 CVSS 9.8 critical · actively exploited Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • CVE-2025-53771 CVSS 6.5 medium Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
  • CVE-2025-53770 CVSS 9.8 critical · actively exploited Microsoft SharePoint Deserialization of Untrusted Data Vulnerability