PatchSiren cyber security CVE debrief
CVE-2026-45467 Microsoft CVE debrief
CVE-2026-45467 is a MEDIUM-severity vulnerability in Microsoft Office SharePoint, with a CVSS score of 4.6. The vulnerability, published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-45467) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-45467), allows an authorized attacker to perform spoofing over a network due to improper neutralization of input during web page generation, also known as cross-site scripting (XSS).
- Vendor
- Microsoft
- Product
- Microsoft SharePoint Enterprise Server 2016
- CVSS
- MEDIUM 4.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-09
- Original CVE updated
- 2026-06-12
- Advisory published
- 2026-06-09
- Advisory updated
- 2026-06-12
Who should care
Administrators and users of Microsoft Office SharePoint Server, particularly those with versions 2016, 2019, and Subscription, should be aware of this vulnerability. The affected versions include [cpeCriteria](https://services.nvd.nist.gov/rest/json/cves/2.0?lastModStartDate=2026-06-09T12%3A30%3A41.000Z&lastModEndDate=2026-06-13T12%3A15%3A54.000Z).
Technical summary
The vulnerability is caused by improper neutralization of input during web page generation, allowing an authorized attacker to inject malicious scripts. The CVSS vector for this vulnerability is [cvssVector](https://nvd.nist.gov/vuln/detail/CVE-2026-45467), indicating a Network attack vector with Low complexity and privileges.
Defensive priority
MEDIUM
Recommended defensive actions
- Apply patches or updates provided by Microsoft to vulnerable SharePoint Server versions.
- Implement proper input validation and sanitization for user-generated content.
- Restrict access to sensitive areas of the SharePoint site for users with lower privileges.
Evidence notes
The CVE record [cve-org] and NVD detail [nvd] provide additional information on this vulnerability, including references to vendor advisories [ref-4].
Official resources
-
CVE-2026-45467 CVE record
CVE.org
-
CVE-2026-45467 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
CVE-2026-45467 was published on 2026-06-09T17:17:21.213Z and last modified on 2026-06-12T16:09:51.143Z.