The short version: Critical SharePoint RCE with public exploit since July 20, 2026 under active exploitation – immediate patches and credential rotation required.
Microsoft released a security update on July 14, 2026 for a critical remote code execution vulnerability in SharePoint Server. Six days later, a functioning exploit code was publicly disclosed and first successful attacks were documented.
Microsoft published a security update on July 14, 2026 to fix a critical remote code execution vulnerability in Microsoft SharePoint Server. CERT-EU observed rapid escalation: On July 20, 2026, WatchTowr identified a functional proof-of-concept exploit, followed by documented successful attack instances.
For CISOs, this creates an immediate risk. The availability of public exploit code coupled with active exploitation indicates that attackers are already deploying the vulnerability in attack scenarios. SharePoint servers that are or were reachable on the Internet must be considered potentially compromised – particularly if the critical period between July 14 and 20 passed without a patch.
CERT-EU urgently recommends immediately updating affected servers and rotating credentials for all accounts that were active on potentially exposed and vulnerable systems. Additionally, the infrastructure should be examined for signs of unauthorized access and lateral movement.
Source: cert.europa.eu · Published July 22, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.