PatchSiren cyber security CVE debrief
CVE-2026-62837 Microsoft CVE debrief
Microsoft SharePoint Server Information Disclosure Vulnerability allows an authorized attacker to disclose information over a network due to a relative path traversal issue. This vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Defenders managing SharePoint Server installations should verify affected versions and apply patches to prevent potential exploitation and data breaches. The vulnerability has a medium severity and is being actively monitored by defenders.
- Vendor
- Microsoft
- Product
- Microsoft SharePoint Enterprise Server 2016
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-10-08
Who should care
Defenders managing SharePoint Server installations, particularly those using Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition.
Why it matters
CVE-2026-62837 is a medium-severity vulnerability in Microsoft SharePoint Server that allows an authorized attacker to disclose information over a network. Defenders managing SharePoint Server installations should verify affected versions, apply patches, and monitor for unauthorized access attempts to prevent potential exploitation and data breaches.
- Verify affected SharePoint Server versions to assess exposure
- Apply patches to prevent information disclosure
- Monitor for unauthorized access attempts to detect potential exploitation
- Review and update incident response plans to address potential data breaches
Technical summary
A relative path traversal vulnerability in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. The vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Defenders should prioritize verifying affected SharePoint Server versions and applying vendor patches to prevent potential exploitation and data breaches.
Defensive priority
Defenders should prioritize verifying affected SharePoint Server versions and applying vendor patches.
Recommended defensive actions
- Verify affected SharePoint Server versions
- Apply vendor patches
- Monitor for unauthorized access attempts
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but vendor advisory details are limited. The vulnerability was disclosed on 2026-08-11 and has not been modified since then. Defenders should verify the affected SharePoint Server versions and apply vendor patches to prevent information disclosure. The CVE Program record and NVD entry provide source-provided CVE metadata and official vulnerability assessment. Additional information may be available from vendor advisori
Sources and references
Verified primary and authoritative sources
-
CVE-2026-62837 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-62837
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-62837 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62837
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Microsoft SharePoint Server Information Disclosure Vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/62xxx/CVE-2026-62837.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62837
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.