# 2026-009: Critical Vulnerabilities in Microsoft SharePoint

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: CERT-EU
- Category: Vulnerabilities
- Original publication time: 2026-07-23T07:13:03Z
- First observed by NexusTechWire: 2026-10-01T17:27:53Z
- Original source: https://cert.europa.eu/publications/security-advisories/2026-009/
- NexusTechWire record: https://nexustechwire.com/news/news-58275f01b5d12802890b

## From the publisher

\[UPDATED\] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.

Source license: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Publisher excerpt shortened and converted to plain text. Original source license applies.

Read the full original: [CERT-EU](https://cert.europa.eu/publications/security-advisories/2026-009/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
