CERT-EU has issued a fresh warning about critical vulnerabilities in Microsoft SharePoint Server, saying one of the flaws is now being actively exploited. The advisory follows Microsoft’s security updates from 14 July 2026, which addressed remote code execution issues in the product.
On 20 July 2026, WatchTowr identified proof-of-concept exploit code and later observed active exploitation of CVE-2026-50522, according to CERT-EU. The agency says the vulnerability is part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances.
Those earlier flaws include CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU’s advisory places the new issue in the same broader pattern of SharePoint weaknesses that have drawn attacker attention this year.
Microsoft’s July update was aimed at critical RCE vulnerabilities in SharePoint Server, but CERT-EU’s notice indicates that patching alone may not be enough for organizations that were exposed before remediation. The agency specifically recommends rotating credentials for any assets that may have been exposed to the internet and conducting a compromise assessment.
Why this matters
SharePoint is widely used in enterprise and government environments, which makes active exploitation especially sensitive. A remotely exploitable flaw in a collaboration platform can create a fast path from a single internet-facing server to broader access inside an organization.
That risk is heightened when attackers can weaponize public exploit code soon after disclosure. In CERT-EU’s view, the combination of proof-of-concept code and confirmed exploitation means administrators should treat affected systems as potentially compromised, not merely vulnerable.
The advisory also fits a broader 2026 pattern in which CERT-EU has repeatedly warned about severe flaws in widely deployed infrastructure products. Its guidance consistently emphasizes immediate remediation, evidence preservation where appropriate, and follow-up investigation when exposure may already have occurred.
For administrators, the practical next step is clear: update affected SharePoint servers immediately, focus first on internet-facing systems, and assume credentials on exposed assets may need to be changed. CERT-EU’s warning suggests the window between disclosure and real-world abuse is already closed.
Looking ahead, the advisory is likely to keep pressure on organizations that run on-premise SharePoint rather than managed cloud alternatives. As long as active exploitation continues, incident responders will need to pair patching with forensic review and account hygiene to reduce the chance of lingering access.