CVE-2026-70332Disclosure(microsoft / sharepoint_online)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft sharepoint_online systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_online

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-07); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
sharepoint_online

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-06: 1Mentions · 2026-08-07: 2Mentions · 2026-08-08: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-08: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-08: 108-0608-0708-08
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-061
General1
2026-08-072
Disclosure2
2026-08-081
Patch1
Full discourse4 posts
  • Sami Laiho@samilaiho
    Patch

    Microsoft Office SharePoint Spoofing Vulnerability URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6

    Post summary

    The note highlights Microsoft’s advisory for CVE-2026-70332, a critical spoofing flaw in SharePoint with an official fix available, but it provides no proof‑of‑concept, exploit code, or evidence of active exploitation.

    000101.0K
    30.6K followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-70332](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332) Server-sid... https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332 #CVE #ZeroDay #PatchManagement

    Post summary

    The tweet announces CVE‑2026‑70332 and directs readers to Microsoft’s update guide, indicating the vulnerability has been disclosed and a patch is available.

    0000043
    18 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-70332 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-70332

    Post summary

    A new SSRF vulnerability (CVE-2026-70332) in Microsoft Office SharePoint enables unauthenticated attackers to perform spoofing over a network.

    00000847
    57.9K followersView on X
  • Windows Forum@windowsforum
    General

    🚨 Microsoft published a SharePoint spoofing CVE with no affected versions, fixes, CVSS, workaround—or useful instructions. For admins, it’s less “security update” and more “please stand by.” https://windowsforum.com/security-alerts.84/cve-2026-70332-sharepoint-spoofing-no-fix-or-affected-versions.441879/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #VulnerabilityManagement #SharepointSecurity #CveTracking https://t.co/Wmt30hFTio

    Post summary

    Microsoft announced a new SharePoint spoofing vulnerability (CVE‑2026‑70332) that currently has no known affected versions, fixes, or workarounds, advising administrators to monitor the situation.

    0000062
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_online---

Explore more