轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000009
[內容說明]
Microsoft SharePoint Server 是一款企業級協作平台,提供文件管理與團隊協作等功能,是企業資訊整合的核心平台。近期微軟發布重大資安公告(CVE-2026-58644,CVSS:9.8 和 CVE-2026-55040,CVSS:9.1),CVE-2026-58644為不受信任資料之反序列化漏洞,允許未經授權的攻擊者透過網路執行任意程式碼;CVE-2026-55040為弱身份驗證漏洞,允許未經授權的攻擊者透過網路繞過安全功能。
[影響平台]
Microsoft SharePoint Server Subscription Edition、 Microsoft SharePoint Server 2019、 Microsoft SharePoint Enterprise Server 2016
[建議措施]
根據官方網站釋出解決方式進行修補:
【CVE-2026-58644】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
【CVE-2026-55040】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
Forwarded Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000009
[Description]
Microsoft SharePoint Server is an enterprise-level collaboration platform that provides functions such as document management and team collaboration, and serves as a core platform for enterprise information integration. Recently, Microsoft released a critical security advisory (CVE-2026-58644, CVSS: 9.8 and CVE-2026-55040, CVSS: 9.1). CVE-2026-58644 is a deserialization of untrusted data vulnerability, allowing unauthorized attackers to execute arbitrary code over the network; CVE-2026-55040 is a weak authentication vulnerability, allowing unauthorized attackers to bypass security features over the network.
[Affected Platforms]
Microsoft SharePoint Server Subscription Edition、 Microsoft SharePoint Server 2019、 Microsoft SharePoint Enterprise Server 2016
[Recommended Actions]
Apply patches according to the solutions provided on the official website:
【CVE-2026-58644】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
【CVE-2026-55040】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040