certeu-2026-009
certeu[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644.<br> CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.<br>
- Published
- Thu, 23 Jul 2026 09:13:03 CEST
- Last Modified
- Thu, 23 Jul 2026 09:13:03 CEST
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"datePublished": "Thu, 23 Jul 2026 09:13:03 CEST",
"description": "[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644.<br>\nCERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.<br>",
"id": "CERTEU-2026-009",
"link": "https://cert.europa.eu/publications/security-advisories/2026-009/",
"source": "certeu",
"title": "2026-009: Critical Vulnerabilities in Microsoft SharePoint"
}