2026-009: Critical Vulnerabilities in Microsoft SharePoint

Imported from official source

Advisory

Cybersecurity Classified by Officially

Critical Vulnerabilities in Microsoft SharePoint

  • 22/07/2026 --- v1.0 -- Initial publication
  • 22/07/2026 --- v1.1 -- Updated to include additional actively exploited vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644)
  • [UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522 [2], a vulnerability part of an ongoing series of actively exploited flaws [3] affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644.

    CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.

    [UPDATED] The vulnerability CVE-2026-50522 (CVSS: 9.8) is a critical deserialisation vulnerability in Microsoft SharePoint that allows a remote attacker to execute arbitrary code on affected systems. While Microsoft indicates that exploitation requires some level of authentication [1], recent findings suggest this may not be the case [2, 4].

    [NEW] Over the past month, Microsoft also fixed the following vulnerabilities affecting Microsoft SharePoint Server:

  • CVE-2026-32201: An improper input validation flaw enabling spoofing attacks by an unauthorised user (CVSS: 6.5) [5]. Fixed in April 2026.
  • CVE-2026-45659: A deserialisation of untrusted data vulnerability allowing authenticated remote code execution (CVSS: 8.8) [6]. Fixed in May 2026.
  • CVE-2026-56164: Missing authentication for a critical function, allowing unauthenticated privilege escalation (CVSS: 9.8) [7]. Fixed in July 2026.
  • CVE-2026-58644: A deserialisation vulnerability enabling unauthenticated remote code execution (CVSS: 9.8) [8]. Fixed in July 2026.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-009/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    This publication has changed since it was first published

    2 versions recorded. The original is kept in full — nothing is overwritten.

    1. v2 imported change on current
    2. v1 as first published on

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 15, 2026 20:57
    Versions
    2 recorded
    Identity
    security-advisories-10946

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.