Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe

CERT-EU warns of actively exploited critical SharePoint RCE flaws

In short: CERT-EU has updated its advisory on critical vulnerabilities in Microsoft SharePoint Server, confirming active exploitation of CVE-2026-50522 (CVSS 9.8), a deserialisation flaw allowing remote code execution. This is part of a wider series of recently patched critical bugs — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — affecting on-premise SharePoint Server instances, some exploitable without authentication.

Source: CERT-EUMicrosoftOriginal article ↗

This summary was generated automatically by AI from CERT-EU's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.

What changed?

  • 1CVE-2026-50522: critical deserialisation RCE (CVSS 9.8), actively exploited, authentication requirement disputed
  • 2CVE-2026-32201: input validation spoofing flaw (CVSS 6.5), fixed April 2026
  • 3CVE-2026-45659: authenticated RCE via deserialisation (CVSS 8.8), fixed May 2026
  • 4CVE-2026-56164: unauthenticated privilege escalation via missing auth (CVSS 9.8), fixed July 2026
  • 5CVE-2026-58644: unauthenticated RCE via deserialisation (CVSS 9.8), fixed July 2026
  • 6Affects Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016

Why it matters

On-premise SharePoint instances exposed to the internet are at high risk of remote takeover; CERT-EU recommends immediate patching, credential rotation, and compromise assessments, and suggests reconsidering internet exposure of SharePoint altogether.

What it means for AI agents and contact centers

This is a Microsoft on-premise collaboration product, not part of a typical Asterisk/SIP, Linux, Node.js or cloud AI stack, so direct exposure is unlikely unless an on-premise SharePoint server is used internally — if so, patch immediately, rotate credentials, and remove internet exposure.

Sources

  • CERT-EUOfficialPrimary source
    „2026-009: Critical Vulnerabilities in Microsoft SharePoint“
    Licence: CC BY 4.0 (CERT-EU legal notice; Commission Decision 2011/833/EU) · our summary (content changed)
    Original article →
Published by source
—
Found by our system
2 Oct 2026, 22:23
Summary generated
3 Oct 2026, 20:01

This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy