[Security Vulnerability Alert] Microsoft's SharePoint Server has two major security vulnerabilities.

 
2026/7/23 ~ 2027/1/23
View Count:31

Forwarded Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000009

[Description]
Microsoft SharePoint Server is an enterprise-level collaboration platform that provides functions such as document management and team collaboration, and serves as a core platform for enterprise information integration. Recently, Microsoft released a critical security advisory (CVE-2026-58644, CVSS: 9.8 and CVE-2026-55040, CVSS: 9.1). CVE-2026-58644 is a deserialization of untrusted data vulnerability, allowing unauthorized attackers to execute arbitrary code over the network; CVE-2026-55040 is a weak authentication vulnerability, allowing unauthorized attackers to bypass security features over the network.

[Affected Platforms]
Microsoft SharePoint Server Subscription Edition、 Microsoft SharePoint Server 2019、 Microsoft SharePoint Enterprise Server 2016

[Recommended Actions]
Apply patches according to the solutions provided on the official website:
【CVE-2026-58644】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644

【CVE-2026-55040】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040

Files
Top↑