CVE-2026-69716: Microsoft SharePoint Server

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Affected products

  • Microsoft SharePoint Server: before 16.0.20326.20094 (fixed in 16.0.20326.20094)

Published 2026-09-08. Last modified 2026-09-09.