Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

Cross-Site Scripting Spoofing in Microsoft Office SharePoint

IdentifiersCVE-2026-26105CWE-79· Improper Neutralization of Input…

CVE-2026-26105 is a Microsoft Office SharePoint spoofing vulnerability caused by improper neutralization of input during web page generation, i.e., a cross-site scripting (XSS) flaw. The available content indicates that a remote, unauthorized attacker can exploit the issue over a network by causing malicious script to be rendered and executed in a victim user’s browser within the context of SharePoint. The vulnerability affects SharePoint’s web page generation path and can be used to present attacker-controlled content as if it were trusted SharePoint content, enabling browser-session script execution and spoofing of SharePoint pages or actions.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to execute script in the context of a victim’s SharePoint browser session, enabling spoofing of trusted SharePoint content and actions. This can facilitate impersonation of legitimate SharePoint pages, theft of session-associated data accessible to the browser context, and user deception that may lead to further compromise of workflows or credentials. The provided content classifies the issue as a spoofing vulnerability rather than direct server-side code execution.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by limiting access to vulnerable SharePoint instances, especially from untrusted networks, and by warning users not to open untrusted or unexpected SharePoint links. Employ browser-side and application-layer defenses where available, such as content filtering, URL inspection, and monitoring for suspicious SharePoint pages or links. Because the issue requires delivery of malicious web content to a user, user-awareness controls and restricting unnecessary SharePoint exposure can reduce risk until patches are applied.

Remediation

Patch, then assume compromise.

Apply the Microsoft security update for CVE-2026-26105 released as part of the March 2026 Patch Tuesday updates for Microsoft SharePoint/Office SharePoint. Microsoft’s bulletin indicates this vulnerability is addressed by the vendor patch; organizations should deploy the relevant SharePoint security update through normal patch management processes and verify installation across affected SharePoint instances.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationOffice Sharepointapplication
Microsoft CorporationSharepoint Enterprise Serverapplication
Microsoft CorporationSharepoint Serverapplication
Microsoft CorporationSharepoint Server 2016application
Microsoft CorporationSharepoint Server 2019application

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity1

Community discussion across Reddit, Mastodon, and other social sources.