CVE-2026-69636: Microsoft SharePoint Server
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Affected products
- Microsoft SharePoint Server: before 16.0.20326.20082 (fixed in 16.0.20326.20082)
Published 2026-09-08. Last modified 2026-09-09.