Multiple Critical Vulnerabilities Discovered in Microsoft SharePoint
Microsoft has released security updates for two critical vulnerabilities in SharePoint that could allow an unauthenticated attacker to execute arbitrary code on affected systems.
English Brief
Microsoft has released security updates for two critical vulnerabilities in SharePoint that could allow an unauthenticated attacker to execute arbitrary code on affected systems.
الموجز العربي
اكتشاف ثغرات أمنية حرجة متعددة في Microsoft SharePoint
أصدرت شركة مايكروسوفت تحديثات أمنية لمعالجة ثغرتين حرجتين في برنامج SharePoint، حيث يمكن استغلالهما من قبل مهاجم غير مصرح له لتنفيذ أوامر برمجية على الأنظمة المتأثرة.
- 1Navigate to the Microsoft Security Update Guide (https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-008/). # 2. Identify current SharePoint version build number. # 3. Download and install the cumulative security updates released on July 14, 2026. # 4. Verify successful installation via SharePoint Central Administration. # 5. Monitor IIS logs for suspicious requests targeting SharePoint endpoints.
English Advisory
// Intelligence Summary
On July 14, 2026, Microsoft issued security patches addressing two critical vulnerabilities (CVE-2026-50522 and CVE-2026-58644) within the SharePoint platform. These vulnerabilities allow for remote code execution (RCE) by an unauthenticated attacker.
التقرير العربي
// ملخص استخباراتي
في 14 يوليو 2026، أصدرت مايكروسوفت تصحيحات أمنية لمعالجة ثغرتين حرجتين (CVE-2026-50522 و CVE-2026-58644) ضمن منصة SharePoint، والتي تسمح لمهاجم غير مصرح له بتنفيذ تعليمات برمجية عن بُعد.
// Technical Context
The vulnerabilities are categorized as critical because they permit unauthenticated remote code execution. This typically involves the manipulation of serialized data or improper handling of requests within the SharePoint framework, allowing the execution of arbitrary commands with the privileges of the SharePoint service account.
// السياق الفني
تُصنف هذه الثغرات ضمن فئة الخطورة الحرجة نظرًا لأنها تتيح تنفيذ تعليمات برمجية عن بُعد دون الحاجة إلى مصادقة، وعادة ما يرتبط هذا النوع من الثغرات بمعالجة غير آمنة للبيانات أو الطلبات داخل إطار عمل SharePoint، مما يسمح بتنفيذ أوامر بامتيازات حساب الخدمة الخاص بـ SharePoint.
// Exposure Notes
Organizations running on-premises versions of Microsoft SharePoint are at highest risk. Administrators should verify the current patch level of their installations against Microsoft's July 2026 security bulletin.
// ملاحظات التعرض
تواجه المؤسسات التي تستخدم إصدارات SharePoint المثبتة محلياً (on-premises) المخاطر الأكبر. يجب على المسؤولين التحقق من مستوى التصحيح الحالي لأنظمتهم ومطابقته مع النشرة الأمنية الصادرة عن مايكروسوفت لشهر يوليو 2026.
// Defensive Priority
Immediate deployment of the July 2026 security updates is the highest priority. Systems should be audited for unauthorized access logs consistent with RCE exploitation attempts.
// أولوية الدفاع
تعتبر الأولوية القصوى هي التثبيت الفوري للتحديثات الأمنية لشهر يوليو 2026، مع ضرورة مراقبة سجلات النظام بحثاً عن أي محاولات وصول غير مصرح بها تدل على استغلال هذه الثغرات.
Mitigation Checklist
- 1Navigate to the Microsoft Security Update Guide (https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-008/). # 2. Identify current SharePoint version build number. # 3. Download and install the cumulative security updates released on July 14, 2026. # 4. Verify successful installation via SharePoint Central Administration. # 5. Monitor IIS logs for suspicious requests targeting SharePoint endpoints.
قائمة إجراءات التخفيف
- 1انتقل إلى دليل تحديثات الأمان الخاص بمايكروسوفت عبر الرابط (https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-008/). # 2. حدد رقم إصدار (Build Number) الخاص بنسخة SharePoint لديك. # 3. قم بتحميل وتثبيت التحديثات الأمنية التراكمية الصادرة بتاريخ 14 يوليو 2026. # 4. تحقق من نجاح عملية التثبيت من خلال وحدة تحكم SharePoint المركزية. # 5. راقب سجلات IIS بحثاً عن طلبات مشبوهة تستهدف نقاط الوصول (endpoints) الخاصة بـ SharePoint.
- Source: CERT-FR Advisories
# 1. Navigate to the Microsoft Security Update Guide (https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-008/). # 2. Identify current SharePoint version build number. # 3. Download and install the cumulative security updates released on July 14, 2026. # 4. Verify successful installation via SharePoint Central Administration. # 5. Monitor IIS logs for suspicious requests targeting SharePoint endpoints.