CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-70130

highCVSS 8.4covered by 3 sourcesfirst seen 2026-08-11
Microsoft has patched vulnerabilities in various Office products. An attacker can exploit the vulnerabilities to conduct attacks that may result in the damage categories described in the table below. Successful exploitation requires the attacker to trick the victim into opening a malicious file or following a link. The table below mentions the vulnerability with identifier CVE-2026-65667 with a CVSS score of 10.0. It also lists vulnerabilities with identifiers CVE-2026-50515, CVE-2026-62896 and CVE-2026-70332, each with a CVSS score of 9 or higher. However, these vulnerabilities have already been centrally patched by Microsoft and are included for informational purposes only. No action is required for these. The vulnerability with identifier CVE-2026-70306 also has a CVSS score higher than 9 and does require action. This vulnerability is located in Sharepoint and allows an attacker to execute arbitrary code in the victim's context through a cross-site scripting attack. Microsoft OneDrive: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65680 | 6.70 | Privilege escalation | |----------------|------|-------------------------------------| Azure SQL Managed Instance: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-62836 | 8.70 | Privilege escalation | |----------------|------|-------------------------------------| Microsoft Teams for Android: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65768 | 8.80 | Arbitrary code execution | | CVE-2026-65767 | 8.80 | Impersonation of other users | |----------------|------|-

CSIRTS triage

What
Multiple vulnerabilities in Office products allow remote code execution and information disclosure; CVE-2026-70306 in SharePoint requires action.
Who is affected
Microsoft Office users and SharePoint deployments are affected; exploitation requires user interaction.
Urgency
High—CVE-2026-70306 (CVSS 9+) in SharePoint requires action and has not been pre-patched centrally.
Action
Prioritize patching of CVE-2026-70306 in SharePoint; verify status of other Office vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-70130

Get an email if CVE-2026-70130 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-70130

CVE.org record

Embed the live status

CVE-2026-70130 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-70130 status](https://www.csirts.com/badge/CVE-2026-70130)](https://www.csirts.com/cve/CVE-2026-70130)