CVE-2026-70355Disclosure(microsoft / sharepoint_server)

LOWCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft sharepoint_server systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
sharepoint_server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-11: 1Mentions · 2026-08-12: 1Active Exploitation · 2026-08-12: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 108-1108-12
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-111
Disclosure1
2026-08-121
Active Exploitation1
Full discourse2 posts
  • FoSo | Cyber@FosoTweets
    Active Exploitation

    Recent SharePoint CVEs (2026) CVE-2026-45659: A high-severity remote code execution flaw affecting on-premises SharePoint Server. It allows authenticated users with basic access to run code, and CISA confirmed active ransomware exploitation. CVE-2026-58644: A critical (CVSS 9.8) remote code execution vulnerability caused by the deserialization of untrusted data, allowing unauthenticated attackers to execute arbitrary code. CVE-2026-55040: A weak authentication/authentication bypass flaw in the JWT token validation pipeline that permits remote unauthenticated attackers to perform operations as a site user or administrator. CVE-2026-50522: A critical 9.8-rated deserialization remote code execution flaw actively targeted by global threat actors to deploy webshells and establish persistence. CVE-2026-56164: A zero-day defect flagged as actively exploited in the wild. CVE-2026-70355: A cross-site scripting vulnerability disclosed in August 2026. #CVE #SharePoint

    Post summary

    Several SharePoint CVEs are disclosed, many with high CVSS scores and remote code execution weaknesses; key CVEs such as 2026‑45659, 2026‑50522, and 2026‑56164 are confirmed to be actively exploited in the wild.

    00000125
    338 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-70355 Privilege Escalation via Cross-Site Scripting in Microsoft Office SharePoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-70355

    Post summary

    CVE‑2026‑70355 is described as a privilege escalation vulnerability via XSS in Microsoft Office SharePoint, with no further technical or operational details provided.

    00000110
    4.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2019--

Explore more