Microsoft has released security updates addressing two critical vulnerabilities in SharePoint, CVE-2026-50522 and CVE-2026-58644, affecting specific versions of SharePoint Enterprise Server 2016, SharePoint Server 2019, and Subscription Edition. These flaws allow remote code execution, with CVE-2026-58644 actively exploited, according to Microsoft. Security firm watchTowr confirmed public proof-of-concept code and active exploitation of CVE-2026-50522. CERT-FR urges immediate patching of affected systems and recommends changing secrets, including ASP.NET machine keys, to mitigate potential post-update compromises. Affected systems include SharePoint Enterprise Server 2016 versions prior to 16.0.5556.1005 and 16.0.5561.1001, SharePoint Server 2019 versions prior to 16.0.10417.20153 and 16.0.10417.20175, and Subscription Edition versions prior to 16.0.19725.20384 and 16.0.19725.20434. Patches are available via Microsoft’s security bulletins.
Summary of content from
Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.