Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026071604071818 | Publication Time | 2026-07-16 16:30:19 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-07-16 16:30:19 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Microsoft SharePoint Server Contains Two Critical Cybersecurity Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000009 Microsoft SharePoint Server is an enterprise-level collaboration platform that provides functions such as document management and team collaboration, and serves as a core platform for enterprise information integration. Recently, Microsoft issued critical cybersecurity advisories regarding CVE-2026-58644 (CVSS: 9.8) and CVE-2026-55040 (CVSS: 9.1). CVE-2026-58644 is a deserialization of untrusted data vulnerability that allows an unauthorised attacker to execute arbitrary code over the network. CVE-2026-55040 is a weak authentication vulnerability that allows an unauthorised attacker to bypass security features over the network. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Microsoft SharePoint Server Subscription Edition Microsoft SharePoint Server 2019 Microsoft SharePoint Enterprise Server 2016 |
|||
|
[Recommended Actions] Apply the patches according to the remediation instructions released on the official website: 【CVE-2026-58644】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644 【CVE-2026-55040】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040 |
|||
|
[Reference] |
|||