Back to list

2026-009 Critical Vulnerabilities in Microsoft SharePoint — CERT-EU-SA2026-009

CERT-EU · CERT-EU · CERT-EU-SA2026-009

ID
CERT-EU-SA2026-009
Date
Source
CERT-EU
Vendor
CERT-EU
Threat
critical
Exploited
Yes

Summary

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances,…

Timeline

Published by source
2026-07-23

Risk context

  • The source data marks this issue as actively exploited; remediation should be prioritized.
  • Reported severity or threat level: critical.
  • Review exposure for the affected product or family: Security advisory.

Product

Security advisory

What to do

General, cautious steps (verify details in the official source):

  • Prioritize patching or mitigation immediately (treat as actively risky).
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Check logs/telemetry for indicators of compromise and suspicious activity.
  • Consider temporary hardening: restrict access, reduce attack surface, and monitor aggressively.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Evidence and provenance

Canonical advisory ID
CERT-EU-SA2026-009
Source
CERT-EU
Vendor
CERT-EU
Published by source
2026-07-23
Last source activity
2026-07-23
Additional identifiers
CVE-2026-50522
Curated by
hlukh.ch

Related advisories and connections

These advisories are connected by shared CVE, product, vendor, source, or time signals.