CVE-2026-62829 is a medium-severity vulnerability (CVSS 4.6).
Summary
Improper neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Affected tools we track
This advisory affects Microsoft. Review the vendor page for current pricing, alternatives and status.
Remediation
Apply the vendor’s update during your next patch window and verify exposure. Patch-management tools that can deploy and verify the fix include Action1, Automox, ManageEngine Patch Manager Plus, ManageEngine Endpoint Central. See our best patch management ranking.