2026-009 Critical Vulnerabilities in Microsoft SharePoint — CERT-EU-SA2026-009
CERT-EU · CERT-EU · CERT-EU-SA2026-009
ID
CERT-EU-SA2026-009
CERT-EU-SA2026-009
Date
Source
CERT-EU
CERT-EU
Vendor
CERT-EU
CERT-EU
Threat
critical
critical
Exploited
Yes
Yes
Summary
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances,…
Timeline
- Published by source
- 2026-07-23
Risk context
- The source data marks this issue as actively exploited; remediation should be prioritized.
- Reported severity or threat level: critical.
- Review exposure for the affected product or family: Security advisory.
Product
Security advisory
What to do
General, cautious steps (verify details in the official source):
- Prioritize patching or mitigation immediately (treat as actively risky).
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Check logs/telemetry for indicators of compromise and suspicious activity.
- Consider temporary hardening: restrict access, reduce attack surface, and monitor aggressively.
- Read the official advisory for exact affected versions and remediation steps.
Official advisory
Evidence and provenance
- Canonical advisory ID
- CERT-EU-SA2026-009
- Source
- CERT-EU
- Vendor
- CERT-EU
- Published by source
- 2026-07-23
- Last source activity
- 2026-07-23
- Additional identifiers
- CVE-2026-50522
- Curated by
- hlukh.ch
Related advisories and connections
These advisories are connected by shared CVE, product, vendor, source, or time signals.