Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY254 SECURITY RECORDS

Microsoft Corporation

Microsoft SharePoint Enterprise Server 2016

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-47636 9 Jun 2026 Microsoft SharePoint Enterprise Server 2016: 16.0.0 < 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 < 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 < 16.0.19725.20384 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-47298 9 Jun 2026 Microsoft SharePoint Enterprise Server 2016: 16.0.0 < 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 < 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 < 16.0.19725.20384 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-45453 9 Jun 2026 Microsoft SharePoint Enterprise Server 2016: 16.0.0 < 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 < 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 < 16.0.19725.20384 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-45483 9 Jun 2026 Microsoft SharePoint Enterprise Server 2016: 16.0.0 < 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 < 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 < 16.0.19725.20384 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-45479 9 Jun 2026 Microsoft SharePoint Enterprise Server 2016: 16.0.0 < 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 < 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 < 16.0.19725.20384 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-45468 9 Jun 2026 Microsoft SharePoint Enterprise Server 2016: 16.0.0 < 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 < 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 < 16.0.19725.20384 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-45467 9 Jun 2026 Microsoft SharePoint Enterprise Server 2016: 16.0.0 < 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 < 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 < 16.0.19725.20384 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-47294 1 Jun 2026 16.0.0 < 16.0.5552.1002; 16.0.0 < 16.0.10417.20128; 16.0.0 < 16.0.19725.20280 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-40365 12 May 2026 16.0.0 < 16.0.5552.1002; 16.0.0 < 16.0.10417.20128; 16.0.0 < 16.0.19725.20280 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-40357 12 May 2026 16.0.0 < 16.0.5552.1002; 16.0.0 < 16.0.10417.20128; 16.0.0 < 16.0.19725.20280 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33112 12 May 2026 16.0.0 < 16.0.5552.1002; 16.0.0 < 16.0.10417.20128; 16.0.0 < 16.0.19725.20280 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33110 12 May 2026 16.0.0 < 16.0.5552.1002; 16.0.0 < 16.0.10417.20128; 16.0.0 < 16.0.19725.20280 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-40368 12 May 2026 16.0.0 < 16.0.5552.1002; 16.0.0 < 16.0.10417.20128; 16.0.0 < 16.0.19725.20280 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-35439 12 May 2026 16.0.0 < 16.0.5552.1002; 16.0.0 < 16.0.10417.20128; 16.0.0 < 16.0.19725.20280 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20945 14 Apr 2026 Microsoft SharePoint Enterprise Server 2016: 16.0.0 < 16.0.5548.1003; Microsoft SharePoint Server 2019: 16.0.0 < 16.0.10417.20114; Microsoft SharePoint Server Subscription Edition: 16.0.0 < 16.0.19725.20210 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-26106 10 Mar 2026 16.0.0 < 16.0.5543.1000; 16.0.0 < 16.0.10417.20102; 16.0.0 < 16.0.19725.20076 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-26114 10 Mar 2026 16.0.0 < 16.0.5543.1000; 16.0.0 < 16.0.10417.20102 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-26105 10 Mar 2026 16.0.0 < 16.0.5543.1000; 16.0.0 < 16.0.10417.20102; 16.0.0 < 16.0.19725.20076 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-20958 13 Jan 2026 16.0.0 < 16.0.5535.1001; 16.0.0 < 16.0.10417.20083; 16.0.0 < 16.0.19127.20442 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20947 13 Jan 2026 16.0.0 < 16.0.5535.1001; 16.0.0 < 16.0.10417.20083; 16.0.0 < 16.0.19127.20442 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20959 13 Jan 2026 16.0.0 < 16.0.5535.1001; 16.0.0 < 16.0.10417.20083; 16.0.0 < 16.0.19127.20442 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-20951 13 Jan 2026 16.0.0 < 16.0.5535.1001; 16.0.0 < 16.0.10417.20083; 16.0.0 < 16.0.19127.20442 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-62204 11 Nov 2025 16.0.0 < 16.0.5526.1001; 16.0.0 < 16.0.10417.20068; 16.0.0 < 16.0.19127.20338 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-59237 14 Oct 2025 16.0.0 < 16.0.5522.1000; 16.0.0 < 16.0.10417.20059; 16.0.0 < 16.0.19127.20262 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-59228 14 Oct 2025 16.0.0 < 16.0.5522.1000; 16.0.0 < 16.0.10417.20059; 16.0.0 < 16.0.19127.20262 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-54897 9 Sep 2025 16.0.0 < 16.0.5517.1000; 16.0.0 < 16.0.10417.20047; 16.0.0 < 16.0.19127.20100 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-49712 12 Aug 2025 16.0.0 < 16.0.5513.1002; 16.0.0 < 16.0.10417.20041 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2025-53760 12 Aug 2025 16.0.0 < 16.0.5513.1002; 16.0.0 < 16.0.10417.20041; 16.0.0 < 16.0.18526.20518 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-53771 20 Jul 2025 16.0.0 < 16.0.5513.1001; 16.0.0 < 16.0.10417.20037; 16.0.0 < 16.0.18526.20508 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2025-49701 8 Jul 2025 16.0.0 < 16.0.5508.1000; 16.0.0 < 16.0.10417.20027; 16.0.0 < 16.0.18526.20424 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-47172 10 Jun 2025 16.0.0 < 16.0.5504.1001; 16.0.0 < 16.0.10417.20018; 16.0.0 < 16.0.18526.20396 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-47166 10 Jun 2025 16.0.0 < 16.0.5504.1001; 16.0.0 < 16.0.10417.20018; 16.0.0 < 16.0.18526.20396 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-47163 10 Jun 2025 16.0.0 < 16.0.5504.1001; 16.0.0 < 16.0.10417.20018; 16.0.0 < 16.0.18526.20396 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-30384 13 May 2025 16.0.0 < 16.0.5500.1001; 16.0.0 < 16.0.10417.20010; 16.0.0 < 16.0.18526.20286 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-30382 13 May 2025 16.0.0 < 16.0.5500.1001; 16.0.0 < 16.0.10417.20010; 16.0.0 < 16.0.18526.20286 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-30378 13 May 2025 16.0.0 < 16.0.5500.1001; 16.0.0 < 16.0.10417.20010; 16.0.0 < 16.0.18526.20286 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-29976 13 May 2025 16.0.0 < 16.0.5500.1001; 16.0.0 < 16.0.10417.20010; 16.0.0 < 16.0.18526.20286 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-29794 8 Apr 2025 16.0.0 < 16.0.5495.1002; 16.0.0 < 16.0.10417.20003; 16.0.0 < 16.0.18526.20172 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-29793 8 Apr 2025 16.0.0 < 16.0.5495.1002; 16.0.0 < 16.0.10417.20003; 16.0.0 < 16.0.18526.20172 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-21400 11 Feb 2025 16.0.0 < 16.0.5487.1000; 16.0.0 < 16.0.10416.20050; 16.0.0 < 16.0.17928.20396 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-21393 14 Jan 2025 16.0.0 < 16.0.5483.1001; 16.0.0 < 16.0.10416.20041; 16.0.0 < 16.0.17928.20356 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-21348 14 Jan 2025 16.0.0 < 16.0.5483.1001; 16.0.0 < 16.0.10416.20041; 16.0.0 < 16.0.17928.20356 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-21344 14 Jan 2025 16.0.0 < 16.0.5483.1001; 16.0.0 < 16.0.10416.20041; 16.0.0 < 16.0.17928.20356 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-49062 10 Dec 2024 16.0.0 < 16.0.5478.1000; 16.0.0 < 16.0.10416.20026; 16.0.0 < 16.0.17928.20290 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-49070 10 Dec 2024 16.0.0 < 16.0.5478.1000; 16.0.0 < 16.0.10416.20026; 16.0.0 < 16.0.17928.20290 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-49068 10 Dec 2024 16.0.0 < 16.0.5478.1000; 16.0.0 < 16.0.10416.20026; 16.0.0 < 16.0.17928.20290 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-49064 10 Dec 2024 16.0.0 < 16.0.5478.1000; 16.0.0 < 16.0.10416.20026; 16.0.0 < 16.0.17928.20290 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-43503 8 Oct 2024 16.0.0 < 16.0.5469.1000; 16.0.0 < 16.0.10415.20001; 16.0.0 < 16.0.17928.20162 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-43466 10 Sep 2024 16.0.0 < 16.0.5465.1001; 16.0.0 < 16.0.10414.20002; 16.0.0 < 16.0.17928.20086 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-38228 10 Sep 2024 16.0.0 < 16.0.5465.1001; 16.0.0 < 16.0.10414.20002; 16.0.0 < 16.0.17928.20086 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.