{"schema_version":1,"title":"Microsoft SharePoint Server 2019 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 37 vulnerabilities in Microsoft SharePoint Server 2019: 0 in the last 7 days and 26 in the last 90 days, 9 of them critical and 9 exploited in the wild. The most recent, CVE-2026-62826, was published on 16 July 2026.","url":"https://junglewise.ai/threats/technologies/sharepoint-server-2019","json_url":"https://junglewise.ai/threats/technologies/sharepoint-server-2019.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/sharepoint-server-2019","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":13,"all_time":37,"critical":9,"exploited":9,"last_7_days":0,"last_30_days":0,"last_90_days":26,"last_365_days":35},"latest":[{"cve":"CVE-2026-62826","cvss":4.6,"slug":"cve-2026-62826-microsoft-sharepoint-cross-site-scripting-vulnerability","title":"Microsoft SharePoint cross-site scripting vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-16T22:17:52.72+00:00","url":"https://junglewise.ai/threats/cve-2026-62826-microsoft-sharepoint-cross-site-scripting-vulnerability"},{"cve":"CVE-2026-58277","cvss":8.8,"slug":"cve-2026-58277-microsoft-sharepoint-improper-authorization-privilege-escalation","title":"Microsoft SharePoint improper authorization privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:36.873+00:00","url":"https://junglewise.ai/threats/cve-2026-58277-microsoft-sharepoint-improper-authorization-privilege-escalation"},{"cve":"CVE-2026-56157","cvss":5.4,"slug":"cve-2026-56157-microsoft-sharepoint-improper-access-control-spoofing","title":"Microsoft SharePoint improper access control spoofing vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:22.673+00:00","url":"https://junglewise.ai/threats/cve-2026-56157-microsoft-sharepoint-improper-access-control-spoofing"},{"cve":"CVE-2026-55142","cvss":5.5,"slug":"cve-2026-55142-microsoft-office-word-numeric-truncation-information-disclosure","title":"Microsoft Office Word numeric truncation information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:21.273+00:00","url":"https://junglewise.ai/threats/cve-2026-55142-microsoft-office-word-numeric-truncation-information-disclosure"},{"cve":"CVE-2026-55135","cvss":4.6,"slug":"cve-2026-55135-microsoft-office-sharepoint-cross-site-scripting","title":"Microsoft Office SharePoint cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:20.307+00:00","url":"https://junglewise.ai/threats/cve-2026-55135-microsoft-office-sharepoint-cross-site-scripting"},{"cve":"CVE-2026-55132","cvss":7.8,"slug":"cve-2026-55132-microsoft-office-word-double-free-local-code-execution","title":"Microsoft Office Word double free local code execution","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:19.85+00:00","url":"https://junglewise.ai/threats/cve-2026-55132-microsoft-office-word-double-free-local-code-execution"},{"cve":"CVE-2026-55130","cvss":7.8,"slug":"cve-2026-55130-microsoft-office-word-heap-buffer-overflow","title":"Microsoft Office Word heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:19.587+00:00","url":"https://junglewise.ai/threats/cve-2026-55130-microsoft-office-word-heap-buffer-overflow"},{"cve":"CVE-2026-55126","cvss":7.3,"slug":"cve-2026-55126-microsoft-sharepoint-cross-site-scripting-vulnerability","title":"Microsoft SharePoint cross-site scripting vulnerability","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:19.063+00:00","url":"https://junglewise.ai/threats/cve-2026-55126-microsoft-sharepoint-cross-site-scripting-vulnerability"},{"cve":"CVE-2026-55052","cvss":8.8,"slug":"cve-2026-55052-microsoft-sharepoint-privilege-escalation-via-missing","title":"Microsoft SharePoint privilege escalation via missing authorization","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:17.287+00:00","url":"https://junglewise.ai/threats/cve-2026-55052-microsoft-sharepoint-privilege-escalation-via-missing"},{"cve":"CVE-2026-55051","cvss":6.5,"slug":"cve-2026-55051-microsoft-sharepoint-ssrf-information-disclosure","title":"Microsoft SharePoint SSRF information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:17.153+00:00","url":"https://junglewise.ai/threats/cve-2026-55051-microsoft-sharepoint-ssrf-information-disclosure"},{"cve":"CVE-2026-55050","cvss":5.5,"slug":"cve-2026-55050-microsoft-office-word-out-of-bounds-read-information-disclosure","title":"Microsoft Office Word out-of-bounds read information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:17.01+00:00","url":"https://junglewise.ai/threats/cve-2026-55050-microsoft-office-word-out-of-bounds-read-information-disclosure"},{"cve":"CVE-2026-55040","cvss":9.1,"epss":0.1754,"slug":"cve-2026-55040-microsoft-sharepoint-weak-authentication-security-feature-bypass","title":"Microsoft SharePoint weak authentication security feature bypass","severity":"critical","exploited":true,"published_at":"2026-07-14T18:18:15.413+00:00","url":"https://junglewise.ai/threats/cve-2026-55040-microsoft-sharepoint-weak-authentication-security-feature-bypass"},{"cve":"CVE-2026-55034","cvss":7.3,"slug":"cve-2026-55034-microsoft-sharepoint-cross-site-scripting-in-web-page-generation","title":"Microsoft SharePoint cross-site scripting in web page generation","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:14.437+00:00","url":"https://junglewise.ai/threats/cve-2026-55034-microsoft-sharepoint-cross-site-scripting-in-web-page-generation"},{"cve":"CVE-2026-55030","cvss":4.6,"slug":"cve-2026-55030-microsoft-sharepoint-cross-site-scripting-vulnerability","title":"Microsoft SharePoint cross-site scripting vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:13.89+00:00","url":"https://junglewise.ai/threats/cve-2026-55030-microsoft-sharepoint-cross-site-scripting-vulnerability"},{"cve":"CVE-2026-55028","cvss":5.5,"slug":"cve-2026-55028-microsoft-office-out-of-bounds-read-information-disclosure","title":"Microsoft Office out-of-bounds read information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:13.613+00:00","url":"https://junglewise.ai/threats/cve-2026-55028-microsoft-office-out-of-bounds-read-information-disclosure"},{"cve":"CVE-2026-55027","cvss":5.5,"slug":"cve-2026-55027-microsoft-office-out-of-bounds-read-information-disclosure","title":"Microsoft Office out-of-bounds read information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:13.473+00:00","url":"https://junglewise.ai/threats/cve-2026-55027-microsoft-office-out-of-bounds-read-information-disclosure"},{"cve":"CVE-2026-55026","cvss":6.2,"slug":"cve-2026-55026-microsoft-office-integer-overflow-information-disclosure","title":"Microsoft Office integer overflow information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:13.33+00:00","url":"https://junglewise.ai/threats/cve-2026-55026-microsoft-office-integer-overflow-information-disclosure"},{"cve":"CVE-2026-55023","cvss":5.5,"slug":"cve-2026-55023-microsoft-office-out-of-bounds-read-information-disclosure","title":"Microsoft Office out-of-bounds read information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:12.913+00:00","url":"https://junglewise.ai/threats/cve-2026-55023-microsoft-office-out-of-bounds-read-information-disclosure"},{"cve":"CVE-2026-55021","cvss":7.3,"slug":"cve-2026-55021-microsoft-sharepoint-cross-site-scripting-vulnerability","title":"Microsoft SharePoint cross-site scripting vulnerability","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:12.663+00:00","url":"https://junglewise.ai/threats/cve-2026-55021-microsoft-sharepoint-cross-site-scripting-vulnerability"},{"cve":"CVE-2026-55020","cvss":4.6,"slug":"cve-2026-55020-microsoft-sharepoint-cross-site-scripting-vulnerability","title":"Microsoft SharePoint cross-site scripting vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:12.54+00:00","url":"https://junglewise.ai/threats/cve-2026-55020-microsoft-sharepoint-cross-site-scripting-vulnerability"},{"cve":"CVE-2026-55019","cvss":4.6,"slug":"cve-2026-55019-microsoft-sharepoint-cross-site-scripting-spoofing-vulnerability","title":"Microsoft SharePoint cross-site scripting spoofing vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:12.42+00:00","url":"https://junglewise.ai/threats/cve-2026-55019-microsoft-sharepoint-cross-site-scripting-spoofing-vulnerability"},{"cve":"CVE-2026-55016","cvss":4.6,"slug":"cve-2026-55016-microsoft-sharepoint-cross-site-scripting-vulnerability","title":"Microsoft SharePoint cross-site scripting vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-14T18:18:12.04+00:00","url":"https://junglewise.ai/threats/cve-2026-55016-microsoft-sharepoint-cross-site-scripting-vulnerability"},{"cve":"CVE-2026-58644","cvss":9.8,"epss":0.013,"slug":"cve-2026-58644-microsoft-sharepoint-remote-code-execution-via-untrusted","title":"Microsoft SharePoint remote code execution via untrusted deserialization","severity":"critical","exploited":true,"published_at":"2026-07-14T17:17:14.257+00:00","url":"https://junglewise.ai/threats/cve-2026-58644-microsoft-sharepoint-remote-code-execution-via-untrusted"},{"cve":"CVE-2026-56164","cvss":5.3,"slug":"cve-2026-56164-microsoft-sharepoint-missing-authentication-in-critical-function","title":"Microsoft SharePoint missing authentication in critical function","severity":"critical","exploited":true,"published_at":"2026-07-14T17:17:09.907+00:00","url":"https://junglewise.ai/threats/cve-2026-56164-microsoft-sharepoint-missing-authentication-in-critical-function"},{"cve":"CVE-2026-54108","cvss":6.5,"slug":"cve-2026-54108-microsoft-sharepoint-spoofing-via-external-control-of-file-path","title":"Microsoft SharePoint spoofing via external control of file path","severity":"medium","exploited":false,"published_at":"2026-07-14T17:17:03.737+00:00","url":"https://junglewise.ai/threats/cve-2026-54108-microsoft-sharepoint-spoofing-via-external-control-of-file-path"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":4,"exploited":4,"vulnerabilities":26},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":963,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Microsoft Edge","slug":"edge-chromium-based","vulnerabilities":167,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"}],"technology":{"hub":true,"name":"Microsoft SharePoint Server 2019","slug":"sharepoint-server-2019","vendor":{"name":"Microsoft","slug":"microsoft","url":"https://junglewise.ai/threats/vendors/microsoft"},"aliases":[],"category":"web-server","homepage":"https://www.microsoft.com/en-us/microsoft-365/sharepoint/collaboration","description":"A collaboration and document management platform for on-premises deployment.","url":"https://junglewise.ai/threats/technologies/sharepoint-server-2019"},"most_severe":[{"cve":"CVE-2026-50522","cvss":9.8,"epss":0.2035,"slug":"cve-2026-50522-microsoft-sharepoint-remote-code-execution-via-unsafe","title":"Microsoft SharePoint remote code execution via unsafe deserialization","severity":"critical","exploited":true,"published_at":"2026-07-14T17:17:01.547+00:00","url":"https://junglewise.ai/threats/cve-2026-50522-microsoft-sharepoint-remote-code-execution-via-unsafe"},{"cve":"CVE-2026-20963","cvss":9.8,"epss":0.0529,"slug":"cve-2026-20963-microsoft-sharepoint-deserialization-of-untrusted-data","title":"Microsoft SharePoint deserialization of untrusted data","severity":"critical","exploited":true,"published_at":"2026-03-18T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-20963-microsoft-sharepoint-deserialization-of-untrusted-data"},{"cve":"CVE-2026-58644","cvss":9.8,"epss":0.013,"slug":"cve-2026-58644-microsoft-sharepoint-remote-code-execution-via-untrusted","title":"Microsoft SharePoint remote code execution via untrusted deserialization","severity":"critical","exploited":true,"published_at":"2026-07-14T17:17:14.257+00:00","url":"https://junglewise.ai/threats/cve-2026-58644-microsoft-sharepoint-remote-code-execution-via-untrusted"},{"cve":"CVE-2026-55040","cvss":9.1,"epss":0.1754,"slug":"cve-2026-55040-microsoft-sharepoint-weak-authentication-security-feature-bypass","title":"Microsoft SharePoint weak authentication security feature bypass","severity":"critical","exploited":true,"published_at":"2026-07-14T18:18:15.413+00:00","url":"https://junglewise.ai/threats/cve-2026-55040-microsoft-sharepoint-weak-authentication-security-feature-bypass"},{"cve":"CVE-2025-49704","cvss":8.8,"epss":0.5958,"slug":"cve-2025-49704-microsoft-sharepoint-code-injection-vulnerability","title":"Microsoft SharePoint code injection vulnerability","severity":"critical","exploited":true,"published_at":"2025-07-22T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-49704-microsoft-sharepoint-code-injection-vulnerability"},{"cve":"CVE-2026-45659","cvss":8.8,"epss":0.0278,"slug":"cve-2026-45659-microsoft-office-sharepoint-deserialization-of-untrusted-data","title":"Microsoft Office SharePoint deserialization of untrusted data","severity":"critical","exploited":true,"published_at":"2026-05-22T23:16:56.273+00:00","url":"https://junglewise.ai/threats/cve-2026-45659-microsoft-office-sharepoint-deserialization-of-untrusted-data"},{"cve":"CVE-2025-49706","cvss":6.5,"epss":0.7499,"slug":"cve-2025-49706-microsoft-sharepoint-improper-authentication-vulnerability","title":"Microsoft SharePoint improper authentication vulnerability","severity":"critical","exploited":true,"published_at":"2025-07-22T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-49706-microsoft-sharepoint-improper-authentication-vulnerability"},{"cve":"CVE-2026-32201","cvss":6.5,"epss":0.0824,"slug":"cve-2026-32201-microsoft-sharepoint-server-improper-input-validation-spoofing","title":"Microsoft SharePoint Server improper input validation spoofing vulnerability","severity":"critical","exploited":true,"published_at":"2026-04-14T18:17:27.16+00:00","url":"https://junglewise.ai/threats/cve-2026-32201-microsoft-sharepoint-server-improper-input-validation-spoofing"},{"cve":"CVE-2026-56164","cvss":5.3,"slug":"cve-2026-56164-microsoft-sharepoint-missing-authentication-in-critical-function","title":"Microsoft SharePoint missing authentication in critical function","severity":"critical","exploited":true,"published_at":"2026-07-14T17:17:09.907+00:00","url":"https://junglewise.ai/threats/cve-2026-56164-microsoft-sharepoint-missing-authentication-in-critical-function"},{"cve":"CVE-2026-40365","cvss":8.8,"epss":0.0007,"slug":"cve-2026-40365-microsoft-sharepoint-remote-code-execution-via-unsafe","title":"Microsoft SharePoint remote code execution via unsafe deserialization","severity":"high","exploited":false,"published_at":"2026-05-12T18:17:15.483+00:00","url":"https://junglewise.ai/threats/cve-2026-40365-microsoft-sharepoint-remote-code-execution-via-unsafe"}],"generated_at":"2026-09-26T09:24:00.138874+00:00"}