1.
CVE-2026-45453: reflected XSS in three SharePoint workflow pages—DocURL is written unencoded into href attributes, executing on hover and enabling session hijacking; fixed in June 2026.
Skip to content
Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-45453.