PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45483 Microsoft CVE debrief

CVE-2026-45483 is a cross-site scripting (XSS) vulnerability in Microsoft Office Project Server. The vulnerability has a CVSS score of 4.6 and a severity rating of MEDIUM. An authorized attacker can exploit this vulnerability to perform spoofing over a network.

Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
CVSS
MEDIUM 4.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-06-09
Advisory published
2026-06-09
Advisory updated
2026-06-09

Who should care

Users of Microsoft Office Project Server should be aware of this vulnerability and take necessary precautions to mitigate the risk.

Technical summary

The vulnerability is caused by improper neutralization of input during web page generation, allowing an attacker to inject malicious code. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N.

Defensive priority

MEDIUM

Recommended defensive actions

  • Apply patches or updates provided by Microsoft to fix the vulnerability.
  • Implement additional security measures, such as input validation and output encoding, to prevent similar vulnerabilities.

Evidence notes

The vendor is listed as Unknown Vendor, but there is evidence suggesting that the product is Microsoft Office Project Server.

Official resources

CVE-2026-45483 was published on 2026-06-09T17:17:22.727Z and modified on 2026-06-09T19:32:51.440Z.