CVE-2026-70324
Microsoft has patched vulnerabilities in various Office products. An attacker can exploit the vulnerabilities to conduct attacks that may result in the damage categories described in the table below. Successful exploitation requires the attacker to trick the victim into opening a malicious file or following a link. The table below mentions the vulnerability with identifier CVE-2026-65667 with a CVSS score of 10.0. It also lists vulnerabilities with identifiers CVE-2026-50515, CVE-2026-62896 and CVE-2026-70332, each with a CVSS score of 9 or higher. However, these vulnerabilities have already been centrally patched by Microsoft and are included for informational purposes only. No action is required for these. The vulnerability with identifier CVE-2026-70306 also has a CVSS score higher than 9 and does require action. This vulnerability is located in Sharepoint and allows an attacker to execute arbitrary code in the victim's context through a cross-site scripting attack.
Microsoft OneDrive: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65680 | 6.70 | Privilege escalation | |----------------|------|-------------------------------------| Azure SQL Managed Instance: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-62836 | 8.70 | Privilege escalation | |----------------|------|-------------------------------------| Microsoft Teams for Android: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65768 | 8.80 | Arbitrary code execution | | CVE-2026-65767 | 8.80 | Impersonation of other users | |----------------|------|-
CSIRTS triage
- What
- Multiple vulnerabilities in Office products allow remote code execution and information disclosure; CVE-2026-70306 in SharePoint requires action.
- Who is affected
- Microsoft Office users and SharePoint deployments are affected; exploitation requires user interaction.
- Urgency
- High—CVE-2026-70306 (CVSS 9+) in SharePoint requires action and has not been pre-patched centrally.
- Action
- Prioritize patching of CVE-2026-70306 in SharePoint; verify status of other Office vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-70324
Get an email if CVE-2026-70324 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Advisory coverage (3)
- unknownNCSC-2026-0286 [1.00] [M/H] Vulnerabilities patched in Microsoft Officencsc-nl · 2026-08-11
- highCVE-2026-70324: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacke…nvd · 2026-08-11
- highCVE-2026-70324: Microsoft SharePoint Elevation of Privilege Vulnerabilitymsrc · 2026-08-11
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-70324)