CERT-EU warns of actively exploited critical SharePoint RCE flaws
In short: CERT-EU has updated its advisory on critical vulnerabilities in Microsoft SharePoint Server, confirming active exploitation of CVE-2026-50522 (CVSS 9.8), a deserialisation flaw allowing remote code execution. This is part of a wider series of recently patched critical bugs — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — affecting on-premise SharePoint Server instances, some exploitable without authentication.
This summary was generated automatically by AI from CERT-EU's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.
What changed?
- 1CVE-2026-50522: critical deserialisation RCE (CVSS 9.8), actively exploited, authentication requirement disputed
- 2CVE-2026-32201: input validation spoofing flaw (CVSS 6.5), fixed April 2026
- 3CVE-2026-45659: authenticated RCE via deserialisation (CVSS 8.8), fixed May 2026
- 4CVE-2026-56164: unauthenticated privilege escalation via missing auth (CVSS 9.8), fixed July 2026
- 5CVE-2026-58644: unauthenticated RCE via deserialisation (CVSS 9.8), fixed July 2026
- 6Affects Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016
Why it matters
On-premise SharePoint instances exposed to the internet are at high risk of remote takeover; CERT-EU recommends immediate patching, credential rotation, and compromise assessments, and suggests reconsidering internet exposure of SharePoint altogether.
What it means for AI agents and contact centers
This is a Microsoft on-premise collaboration product, not part of a typical Asterisk/SIP, Linux, Node.js or cloud AI stack, so direct exposure is unlikely unless an on-premise SharePoint server is used internally — if so, patch immediately, rotate credentials, and remove internet exposure.
Sources
- CERT-EUOfficialPrimary sourceOriginal article →„2026-009: Critical Vulnerabilities in Microsoft SharePoint“Licence: CC BY 4.0 (CERT-EU legal notice; Commission Decision 2011/833/EU) · our summary (content changed)
- Published by source
- —
- Found by our system
- 2 Oct 2026, 22:23
- Summary generated
- 3 Oct 2026, 20:01
This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy