{
    "file_item": {
        "filepath": "security-advisories",
        "filename": "CERT-EU-SA2026-009.pdf"
    },
    "title": "Critical Vulnerability in Microsoft SharePoint",
    "serial_number": "2026-009",
    "publish_date": "22-07-2026 08:39:13",
    "description": "On 14 July 2026, Microsoft released a security update addressing a critical Remote Code Execution (RCE) in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code, and later, successful exploitation attempts.<br>\nCERT-EU strongly recommend to update affected servers and to rotate credentials on any assets that may have been vulnerable and exposed on the internet.<br>\n",
    "url_title": "2026-009",
    "content_markdown": "---    \ntitle: 'Critical Vulnerability in\u00a0Microsoft\u00a0SharePoint'\nnumber: '2026-009'\nversion: '1.0'\noriginal_date: '2026-07-14'\ndate: '2026-07-22'\n---\n\n_History:_\n\n* _22/07/2026 --- v1.0 -- Initial publication_\n\n# Summary\n\nOn 14 July 2026, Microsoft released a security update addressing a critical Remote Code Execution (RCE) in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a **proof-of-concept exploit code**, and later, **successful exploitation attempts** [2].\n\nCERT-EU strongly recommend to update affected servers and to rotate credentials on any assets that may have been vulnerable and exposed on the internet.\n\n# Technical Details\n\nThe vulnerability **CVE-2026-50522**, with a CVSS score of 9.8, is a critical deserialisation vulnerability in Microsoft SharePoint. It allows a remote attacker to execute code on the affected assets.\n\nWhile Microsoft suggests this vulnerability requires some level of authentication [1], recent findings may indicate otherwise [2, 3].\n\n# Affected Products\n\nThis vulnerability affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016 [1].\n\n# Recommendations\n\nCERT-EU strongly recommends to update affected servers as soon as possible, and to run compromise assessment to identify potentially affected SharePoint instances.\n\nCERT-EU also recommends to rotate credentials on any assets that may have been vulnerable and exposed on the internet.\n\nConsidering the number of recent critical RCE vulnerability affecting SharePoint, exposing any SharePoint server on the internet should be reconsidered. \n\n# References\n\n[1] <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522> \n\n[2] <https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/>\n\n[3] <https://x.com/DefusedCyber/status/2079128402855116858>\n",
    "content_html": "<p><em>History:</em></p><ul><li><em>22/07/2026 --- v1.0 -- Initial publication</em></li></ul><h2 id=\"summary\">Summary</h2><p>On 14 July 2026, Microsoft released a security update addressing a critical Remote Code Execution (RCE) in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a <strong>proof-of-concept exploit code</strong>, and later, <strong>successful exploitation attempts</strong> [2].</p><p>CERT-EU strongly recommend to update affected servers and to rotate credentials on any assets that may have been vulnerable and exposed on the internet.</p><h2 id=\"technical-details\">Technical Details</h2><p>The vulnerability <strong>CVE-2026-50522</strong>, with a CVSS score of 9.8, is a critical deserialisation vulnerability in Microsoft SharePoint. It allows a remote attacker to execute code on the affected assets.</p><p>While Microsoft suggests this vulnerability requires some level of authentication [1], recent findings may indicate otherwise [2, 3].</p><h2 id=\"affected-products\">Affected Products</h2><p>This vulnerability affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016 [1].</p><h2 id=\"recommendations\">Recommendations</h2><p>CERT-EU strongly recommends to update affected servers as soon as possible, and to run compromise assessment to identify potentially affected SharePoint instances.</p><p>CERT-EU also recommends to rotate credentials on any assets that may have been vulnerable and exposed on the internet.</p><p>Considering the number of recent critical RCE vulnerability affecting SharePoint, exposing any SharePoint server on the internet should be reconsidered. </p><h2 id=\"references\">References</h2><p>[1] <a rel=\"noopener\" target=\"_blank\" href=\"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522\">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522</a> </p><p>[2] <a rel=\"noopener\" target=\"_blank\" href=\"https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/\">https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/</a></p><p>[3] <a rel=\"noopener\" target=\"_blank\" href=\"https://x.com/DefusedCyber/status/2079128402855116858\">https://x.com/DefusedCyber/status/2079128402855116858</a></p>",
    "licence": {
        "title": "Creative Commons Attribution 4.0 International (CC-BY 4.0)",
        "link": "https://creativecommons.org/licenses/by/4.0/",
        "restrictions": "https://cert.europa.eu/legal-notice",
        "author": "The Cybersecurity Service for the Union institutions, bodies, offices and agencies"
    }
}