2026-009: Critical Vulnerabilities in Microsoft SharePoint
Imported from official source
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.
This version
- Version
- 2 of 2
- Recorded
- September 17, 2026 21:30
- Change
- Imported change
- Content hash
4a1a31ec94306bec19a5ba6c19cc65e0- All versions
- Revision history