2026-009: Critical Vulnerabilities in Microsoft SharePoint
At a glance
- Severity
- Critical
- Used in attacks
- Yes, 5 of 5 flaws named
- Vendors and products
- MicrosoftSharePoint
- Reported by
- 1 outlet
History:
- 22/07/2026 --- v1.0 -- Initial publication
- 22/07/2026 --- v1.1 -- Updated to include additional actively exploited vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644)
Summary
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522 [2], a vulnerability part of an ongoing series of actively exploited flaws [3] affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644.
CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.
Technical Details
[UPDATED] The vulnerability CVE-2026-50522 (CVSS: 9.8) is a critical deserialisation vulnerability in Microsoft SharePoint that allows a remote attacker to execute arbitrary code on affected systems. While Microsoft indicates that exploitation requires some level of authentication [1], recent findings suggest this may not be the case [2, 4].
[NEW] Over the past month, Microsoft also fixed the following vulnerabilities affecting Microsoft SharePoint Server:
- CVE-2026-32201: An improper input validation flaw enabling spoofing attacks by an unauthorised user (CVSS: 6.5) [5]. Fixed in April 2026.
- CVE-2026-45659: A deserialisation of untrusted data vulnerability allowing authenticated remote code execution (CVSS: 8.8) [6]. Fixed in May 2026.
- CVE-2026-56164: Missing authentication for a critical function, allowing unauthenticated privilege escalation (CVSS: 9.8) [7]. Fixed in July 2026.
- CVE-2026-58644: A deserialisation vulnerability enabling unauthenticated remote code execution (CVSS: 9.8) [8]. Fixed in July 2026.
Affected Products
[UPDATED] The vulnerability CVE-2026-50522 affects the following Microsoft SharePoint products. Refer to the respective Microsoft advisories [5–8] for the full list of affected products for the other vulnerabilities.
- Microsoft SharePoint Server Subscription Edition
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Enterprise Server 2016
Recommendations
CERT-EU strongly recommends updating affected servers as soon as possible, rotating credentials for any assets that may have been vulnerable and exposed to the internet, and conducting a compromise assessment to identify potentially affected SharePoint instances.
Given the number of recent critical vulnerabilities affecting SharePoint, organisations should reconsider exposing any Microsoft SharePoint Server directly to the internet.
References
[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
[4] https://x.com/DefusedCyber/status/2079128402855116858
[5] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201
[6] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
[7] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
[8] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
Reproduced in full under licence from CERT-EU. © CERT-EU.
Vulnerabilities referenced
- CVE-2026-32201Not scored yet
Microsoft SharePoint Server
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Used in attacksAdded to CISA's list 2026-04-14
Full record → - CVE-2026-45659Not scored yet
Microsoft SharePoint Server
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Used in attacksUsed by ransomware gangsAdded to CISA's list 2026-07-01
Full record → - CVE-2026-50522Not scored yet
Microsoft SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Used in attacksAdded to CISA's list 2026-07-22
Full record → - CVE-2026-56164Not scored yet
Microsoft SharePoint Server
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Used in attacksAdded to CISA's list 2026-07-14
Full record → - CVE-2026-58644Not scored yet
Microsoft SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Used in attacksAdded to CISA's list 2026-07-16
Full record →
Coverage
One outlet has carried this so far.
time not given by source
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited