{
    "file_item": {
        "filepath": "security-advisories",
        "filename": "CERT-EU-SA2026-009.pdf"
    },
    "title": "Critical Vulnerabilities in Microsoft SharePoint",
    "serial_number": "2026-009",
    "publish_date": "23-07-2026 07:13:03",
    "description": "[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644.<br>\nCERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.<br>\n",
    "url_title": "2026-009",
    "content_markdown": "---    \ntitle: 'Critical Vulnerabilities in\u00a0Microsoft\u00a0SharePoint'\nnumber: '2026-009'\nversion: '1.1'\noriginal_date: '2026-07-14'\ndate: '2026-07-22'\n---\n\n_History:_\n\n* _22/07/2026 --- v1.0 -- Initial publication_\n* _22/07/2026 --- v1.1 -- Updated to include additional actively exploited vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644)_\n\n# Summary\n\n**[UPDATED]** On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of **CVE-2026-50522** [2], a vulnerability part of an ongoing series of actively exploited flaws [3] affecting on-premise SharePoint Server instances, including **CVE-2026-32201**, **CVE-2026-45659**, **CVE-2026-56164**, and **CVE-2026-58644**.\n\nCERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.\n\n# Technical Details\n\n**[UPDATED]** The vulnerability **CVE-2026-50522** (CVSS: 9.8) is a critical deserialisation vulnerability in Microsoft SharePoint that allows a remote attacker to execute arbitrary code on affected systems. While Microsoft indicates that exploitation requires some level of authentication [1], recent findings suggest this may not be the case [2, 4].\n\n**[NEW]** Over the past month, Microsoft also fixed the following vulnerabilities affecting Microsoft SharePoint Server:\n\n- **CVE-2026-32201**: An improper input validation flaw enabling spoofing attacks by an unauthorised user (CVSS: 6.5)\u00a0[5]. Fixed in April 2026.\n- **CVE-2026-45659**: A deserialisation of untrusted data vulnerability allowing authenticated remote code execution (CVSS: 8.8) [6]. Fixed in May 2026.\n- **CVE-2026-56164**: Missing authentication for a critical function, allowing unauthenticated privilege escalation (CVSS: 9.8)\u00a0[7]. Fixed in July 2026.\n- **CVE-2026-58644**: A deserialisation vulnerability enabling unauthenticated remote code execution (CVSS: 9.8) [8]. Fixed in July 2026.\n\n# Affected Products\n\n**[UPDATED]** The vulnerability **CVE-2026-50522** affects the following Microsoft SharePoint products. Refer to the respective Microsoft advisories [5\u20138] for the full list of affected products for the other vulnerabilities.\n\n- Microsoft SharePoint Server Subscription Edition\n- Microsoft SharePoint Server 2019\n- Microsoft SharePoint Enterprise Server 2016\n\n# Recommendations\n\nCERT-EU strongly recommends updating affected servers as soon as possible, rotating credentials for any assets that may have been vulnerable and exposed to the internet, and conducting a compromise assessment to identify potentially affected SharePoint instances.\n\nGiven the number of recent critical vulnerabilities affecting SharePoint, organisations should reconsider exposing any Microsoft SharePoint Server directly to the internet.\n\n# References\n\n[1] <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522>\n\n[2] <https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/>\n\n[3] <https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations>\n\n[4] <https://x.com/DefusedCyber/status/2079128402855116858>\n\n[5] <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201>\n\n[6] <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659>\n\n[7] <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164>\n\n[8] <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644>",
    "content_html": "<p><em>History:</em></p><ul><li><em>22/07/2026 --- v1.0 -- Initial publication</em></li><li><em>22/07/2026 --- v1.1 -- Updated to include additional actively exploited vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644)</em></li></ul><h2 id=\"summary\">Summary</h2><p><strong>[UPDATED]</strong> On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of <strong>CVE-2026-50522</strong> [2], a vulnerability part of an ongoing series of actively exploited flaws [3] affecting on-premise SharePoint Server instances, including <strong>CVE-2026-32201</strong>, <strong>CVE-2026-45659</strong>, <strong>CVE-2026-56164</strong>, and <strong>CVE-2026-58644</strong>.</p><p>CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.</p><h2 id=\"technical-details\">Technical Details</h2><p><strong>[UPDATED]</strong> The vulnerability <strong>CVE-2026-50522</strong> (CVSS: 9.8) is a critical deserialisation vulnerability in Microsoft SharePoint that allows a remote attacker to execute arbitrary code on affected systems. While Microsoft indicates that exploitation requires some level of authentication [1], recent findings suggest this may not be the case [2, 4].</p><p><strong>[NEW]</strong> Over the past month, Microsoft also fixed the following vulnerabilities affecting Microsoft SharePoint Server:</p><ul><li><strong>CVE-2026-32201</strong>: An improper input validation flaw enabling spoofing attacks by an unauthorised user (CVSS: 6.5)\u00a0[5]. Fixed in April 2026.</li><li><strong>CVE-2026-45659</strong>: A deserialisation of untrusted data vulnerability allowing authenticated remote code execution (CVSS: 8.8) [6]. Fixed in May 2026.</li><li><strong>CVE-2026-56164</strong>: Missing authentication for a critical function, allowing unauthenticated privilege escalation (CVSS: 9.8)\u00a0[7]. Fixed in July 2026.</li><li><strong>CVE-2026-58644</strong>: A deserialisation vulnerability enabling unauthenticated remote code execution (CVSS: 9.8) [8]. Fixed in July 2026.</li></ul><h2 id=\"affected-products\">Affected Products</h2><p><strong>[UPDATED]</strong> The vulnerability <strong>CVE-2026-50522</strong> affects the following Microsoft SharePoint products. Refer to the respective Microsoft advisories [5\u20138] for the full list of affected products for the other vulnerabilities.</p><ul><li>Microsoft SharePoint Server Subscription Edition</li><li>Microsoft SharePoint Server 2019</li><li>Microsoft SharePoint Enterprise Server 2016</li></ul><h2 id=\"recommendations\">Recommendations</h2><p>CERT-EU strongly recommends updating affected servers as soon as possible, rotating credentials for any assets that may have been vulnerable and exposed to the internet, and conducting a compromise assessment to identify potentially affected SharePoint instances.</p><p>Given the number of recent critical vulnerabilities affecting SharePoint, organisations should reconsider exposing any Microsoft SharePoint Server directly to the internet.</p><h2 id=\"references\">References</h2><p>[1] <a rel=\"noopener\" target=\"_blank\" href=\"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522\">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522</a></p><p>[2] <a rel=\"noopener\" target=\"_blank\" href=\"https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/\">https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/</a></p><p>[3] <a rel=\"noopener\" target=\"_blank\" href=\"https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations\">https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations</a></p><p>[4] <a rel=\"noopener\" target=\"_blank\" href=\"https://x.com/DefusedCyber/status/2079128402855116858\">https://x.com/DefusedCyber/status/2079128402855116858</a></p><p>[5] <a rel=\"noopener\" target=\"_blank\" href=\"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201\">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201</a></p><p>[6] <a rel=\"noopener\" target=\"_blank\" href=\"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659\">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659</a></p><p>[7] <a rel=\"noopener\" target=\"_blank\" href=\"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164\">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164</a></p><p>[8] <a rel=\"noopener\" target=\"_blank\" href=\"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644\">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644</a></p>",
    "licence": {
        "title": "Creative Commons Attribution 4.0 International (CC-BY 4.0)",
        "link": "https://creativecommons.org/licenses/by/4.0/",
        "restrictions": "https://cert.europa.eu/legal-notice",
        "author": "The Cybersecurity Service for the Union institutions, bodies, offices and agencies"
    }
}