【資安漏洞預警】Microsoft 旗下SharePoint Server 存在2個重大資安漏洞
[Security Vulnerability Alert] Microsoft's SharePoint Server has two major security vulnerabilities.

發布單位:圖資處數位服務組
日期範圍:2026/7/23 ~ 2027/1/23
 
發布單位:圖資處數位服務組
日期範圍:2026/7/23 ~ 2027/1/23
行政 行政公告
全體

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000009

[內容說明]
Microsoft SharePoint Server 是一款企業級協作平台,提供文件管理與團隊協作等功能,是企業資訊整合的核心平台。近期微軟發布重大資安公告(CVE-2026-58644,CVSS:9.8 和 CVE-2026-55040,CVSS:9.1),CVE-2026-58644為不受信任資料之反序列化漏洞,允許未經授權的攻擊者透過網路執行任意程式碼;CVE-2026-55040為弱身份驗證漏洞,允許未經授權的攻擊者透過網路繞過安全功能。

[影響平台]
Microsoft SharePoint Server Subscription Edition、 Microsoft SharePoint Server 2019、 Microsoft SharePoint Enterprise Server 2016

[建議措施]
根據官方網站釋出解決方式進行修補:
【CVE-2026-58644】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644

【CVE-2026-55040】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040

Forwarded Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000009

[Description]
Microsoft SharePoint Server is an enterprise-level collaboration platform that provides functions such as document management and team collaboration, and serves as a core platform for enterprise information integration. Recently, Microsoft released a critical security advisory (CVE-2026-58644, CVSS: 9.8 and CVE-2026-55040, CVSS: 9.1). CVE-2026-58644 is a deserialization of untrusted data vulnerability, allowing unauthorized attackers to execute arbitrary code over the network; CVE-2026-55040 is a weak authentication vulnerability, allowing unauthorized attackers to bypass security features over the network.

[Affected Platforms]
Microsoft SharePoint Server Subscription Edition、 Microsoft SharePoint Server 2019、 Microsoft SharePoint Enterprise Server 2016

[Recommended Actions]
Apply patches according to the solutions provided on the official website:
【CVE-2026-58644】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644

【CVE-2026-55040】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
Top↑