VORANT. Threat Intelligence Sign in Get the full feed

Microsoft SharePoint flaws risk data exposure

medium vulnerability technology

ANSSI warns of two Microsoft vulnerabilities in SharePoint Server and Remote Desktop Web Client that could expose data or bypass security controls.

The French national cybersecurity agency (CERT-FR) has issued an advisory covering two vulnerabilities affecting Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition, and Remote Desktop Web Client. The flaws, tracked as CVE-2026-56171 and CVE-2026-62826, could allow an attacker to compromise data confidentiality and bypass security policy protections on affected systems.

Microsoft published security bulletins for both CVEs on 16 July 2026. No public exploitation or proof-of-concept activity is mentioned in the advisory. Organizations running affected versions of SharePoint or Remote Desktop Web Client are advised to apply the vendor's patches referenced in the official Microsoft security guide.

Mentioned in this report

Vulnerabilities CVE-2026-56171CVE-2026-62826

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0896

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free