Technology · Microsoft
Microsoft SharePoint Server 2019 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 37 vulnerabilities in Microsoft SharePoint Server 2019: 0 in the last 7 days and 26 in the last 90 days, 9 of them critical and 9 exploited in the wild. The most recent, CVE-2026-62826, was published on 16 July 2026.
- Last 7 days
- 0
- Last 90 days
- 26
- Critical, all time
- 9
- Exploited in the wild
- 9
About Microsoft SharePoint Server 2019
A collaboration and document management platform for on-premises deployment.
Latest Microsoft SharePoint Server 2019 vulnerabilities
- CVE-2026-62826: Microsoft SharePoint cross-site scripting vulnerabilitymediumCVSS 4.6
- CVE-2026-58277: Microsoft SharePoint improper authorization privilege escalationhighCVSS 8.8
- CVE-2026-56157: Microsoft SharePoint improper access control spoofing vulnerabilitymediumCVSS 5.4
- CVE-2026-55142: Microsoft Office Word numeric truncation information disclosuremediumCVSS 5.5
- CVE-2026-55135: Microsoft Office SharePoint cross-site scriptingmediumCVSS 4.6
- CVE-2026-55132: Microsoft Office Word double free local code executionhighCVSS 7.8
- CVE-2026-55130: Microsoft Office Word heap buffer overflowhighCVSS 7.8
- CVE-2026-55126: Microsoft SharePoint cross-site scripting vulnerabilityhighCVSS 7.3
- CVE-2026-55052: Microsoft SharePoint privilege escalation via missing authorizationhighCVSS 8.8
- CVE-2026-55051: Microsoft SharePoint SSRF information disclosuremediumCVSS 6.5
- CVE-2026-55050: Microsoft Office Word out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55040: Microsoft SharePoint weak authentication security feature bypasscriticalexploited in the wildCVSS 9.1EPSS 17.5%
- CVE-2026-55034: Microsoft SharePoint cross-site scripting in web page generationhighCVSS 7.3
- CVE-2026-55030: Microsoft SharePoint cross-site scripting vulnerabilitymediumCVSS 4.6
- CVE-2026-55028: Microsoft Office out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55027: Microsoft Office out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55026: Microsoft Office integer overflow information disclosuremediumCVSS 6.2
- CVE-2026-55023: Microsoft Office out-of-bounds read information disclosuremediumCVSS 5.5
- CVE-2026-55021: Microsoft SharePoint cross-site scripting vulnerabilityhighCVSS 7.3
- CVE-2026-55020: Microsoft SharePoint cross-site scripting vulnerabilitymediumCVSS 4.6
- CVE-2026-55019: Microsoft SharePoint cross-site scripting spoofing vulnerabilitymediumCVSS 4.6
- CVE-2026-55016: Microsoft SharePoint cross-site scripting vulnerabilitymediumCVSS 4.6
- CVE-2026-58644: Microsoft SharePoint remote code execution via untrusted deserializationcriticalexploited in the wildCVSS 9.8EPSS 1.3%
- CVE-2026-56164: Microsoft SharePoint missing authentication in critical functioncriticalexploited in the wildCVSS 5.3
- CVE-2026-54108: Microsoft SharePoint spoofing via external control of file pathmediumCVSS 6.5
Most severe Microsoft SharePoint Server 2019 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-50522: Microsoft SharePoint remote code execution via unsafe deserializationcriticalexploited in the wildCVSS 9.8EPSS 20.3%
- CVE-2026-20963: Microsoft SharePoint deserialization of untrusted datacriticalexploited in the wildCVSS 9.8EPSS 5.3%
- CVE-2026-58644: Microsoft SharePoint remote code execution via untrusted deserializationcriticalexploited in the wildCVSS 9.8EPSS 1.3%
- CVE-2026-55040: Microsoft SharePoint weak authentication security feature bypasscriticalexploited in the wildCVSS 9.1EPSS 17.5%
- CVE-2025-49704: Microsoft SharePoint code injection vulnerabilitycriticalexploited in the wildCVSS 8.8EPSS 59.6%
- CVE-2026-45659: Microsoft Office SharePoint deserialization of untrusted datacriticalexploited in the wildCVSS 8.8EPSS 2.8%
- CVE-2025-49706: Microsoft SharePoint improper authentication vulnerabilitycriticalexploited in the wildCVSS 6.5EPSS 75.0%
- CVE-2026-32201: Microsoft SharePoint Server improper input validation spoofing vulnerabilitycriticalexploited in the wildCVSS 6.5EPSS 8.2%
- CVE-2026-56164: Microsoft SharePoint missing authentication in critical functioncriticalexploited in the wildCVSS 5.3
- CVE-2026-40365: Microsoft SharePoint remote code execution via unsafe deserializationhighCVSS 8.8EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 26 | 4 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/sharepoint-server-2019.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft SharePoint Server 2019 vulnerabilities", https://junglewise.ai/threats/technologies/sharepoint-server-2019, 26 September 2026.