2026-009: Critical Vulnerabilities in Microsoft SharePoint
- Actief misbruik
- Niet bevestigd
- Hoogste CVSS
- —
- Kans op misbruik (EPSS)
- —
- Prioriteit
- 0 van 100
Uit de melding
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server.
On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644.
CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.
Lees de volledige melding bij CERT-EU Security AdvisoriesBron: CERT-EU Security Advisories, CC BY 4.0, samengevat en vertaald door Seinwacht.