Skip to main content

CVE-2026-55021

Microsoft SharePoint Server Spoofing vulnerability

Microsoft

MSRC advisory July 14, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-55021
Affected products
Microsoft SharePoint Server Spoofing · Microsoft Microsoft SharePoint Server Spoofing · Microsoft

What happened

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

What it means for your business

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55021) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Sources

Related briefs

Microsoft MSRC

CVE-2026-69492

Windows Partition Management Driver Elevation of Privilege vulnerability

Windows Partition Management Driver Elevation of Privilege vulnerability (CVE-2026-69492) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62693

Windows MIDI Service Module Elevation of Privileges vulnerability

Windows MIDI Service Module Elevation of Privileges vulnerability (CVE-2026-62693) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45499

Azure OpenAI Elevation of Privilege vulnerability

Azure OpenAI Elevation of Privilege vulnerability (CVE-2026-45499) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-85880

Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-85880). Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. CISA remediation due date: 2026-09-22. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.