Microsoft has disclosed CVE-2026-70332, a critical server-side request forgery flaw in Microsoft Office SharePoint that allows an unauthorized attacker to perform spoofing over a network, rated CVSS 9.6.
What Is It
CVE-2026-70332 is a server-side request forgery (SSRF) vulnerability, tracked as CWE-918, in Microsoft Office SharePoint. Per Microsoft's description, the flaw "allows an unauthorized attacker to perform spoofing over a network."
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, producing a base score of 9.6 (CRITICAL) with an exploitability subscore of 2.8 and an impact subscore of 6.0. In plain terms: the attack is launched over the network, requires low complexity and no privileges, but does require user interaction. The scope is Changed, meaning successful exploitation reaches beyond the vulnerable component itself, and confidentiality, integrity, and availability impacts are all rated High.
The record was published by Microsoft ([email protected]) on 2026-08-06 and currently carries NVD vulnerability status "Received," meaning NVD analysis is not yet complete.
Why It Matters
The combination that drives this to 9.6 is no privileges required, low attack complexity, changed scope, and High impact across all three CIA categories. The unauthenticated precondition plus a scope change is the part worth flagging; an attacker does not need an account, and the blast radius extends past the SharePoint component.
The mitigating factor is that user interaction is required, so exploitation is not fully hands-off.
CVE-2026-70332 does not appear in the CISA Known Exploited Vulnerabilities catalog as of this brief's publication (see Sources). There is no confirmation of active exploitation in the wild at this time.
What's Vulnerable
Microsoft lists the affected product as Microsoft SharePoint Online, version - (all), status affected. No affected CPE entries were present in the NVD record.
Microsoft tagged this CVE as exclusively-hosted-service. That tag indicates the vulnerability exists in a Microsoft-hosted service rather than in customer-deployed software.
Patch Status
No patch guidance, remediation steps, or required-action deadline are present in the supplied source material. The only vendor reference is the MSRC update guide entry below; consult it directly for current remediation status. Because the CVE is tagged as an exclusively hosted service, customer-side patching may not apply.
Sources
- NVD, CVE-2026-70332: https://nvd.nist.gov/vuln/detail/CVE-2026-70332
- Microsoft MSRC Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog