| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Sharepoint products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-56164 | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | 9.8 | 999 | Neutral | Yes | Yes |
| CVE-2026-48562 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 4.6 | 203 | Neutral | No | Yes |
| CVE-2026-48560 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 245 | Neutral | No | Yes |
| CVE-2026-47641 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 202 | Neutral | No | Yes |
| CVE-2026-47640 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-47639 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-47638 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-47637 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-47636 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-47634 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-47298 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 8.0 | 498 | Neutral | No | Yes |
| CVE-2026-47294 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 8.0 | 618 | Neutral | No | Yes |
| CVE-2026-45659 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 8.8 | 775 | Low | Yes | Yes |
| CVE-2026-45485 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 3.3 | 180 | Neutral | No | Yes |
| CVE-2026-45484 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 8.8 | 673 | Neutral | No | Yes |
| CVE-2026-45483 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-45481 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-45479 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-45475 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 7.8 | 431 | Neutral | No | Yes |
| CVE-2026-45471 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 7.8 | 431 | Neutral | No | Yes |