CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-21264

CVSS 9.3v3.1pub. 2026-01-22upd. 2026-02-03

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.

🤖 AI Analysis
How it works

The vulnerability stems from improper neutralization of input data during web page generation (CWE-79). An attacker can inject malicious script code that will be executed in the victim's browser context after interaction with prepared content. Due to the changed scope (S:C in the CVSS vector), the effects of script execution may extend beyond the source domain, enabling, among other things, impersonation of legitimate Microsoft Account content.

Impact

An attacker can gain access to sensitive user information (high confidentiality) and make unauthorized modifications to content or impersonate trusted resources (high integrity). The attack requires user interaction, such as clicking on a crafted link.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21264. As supplementary measures, it is recommended to exercise caution when clicking on links to Microsoft Account pages from untrusted sources.

Who is affected

Microsoft Account service — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Microsoft Account

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-56165CRITICAL9.8PL ✓same product

Heap-based buffer overflow w Microsoft Account umożliwiający zdalne wykonanie kodu

CVE-2025-21396HIGH8.2same product

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a networ...

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-58644CRITICAL9.8⚠ KEVPL ✓same vendor

Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server