PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62837 Microsoft CVE debrief

Microsoft SharePoint Server Information Disclosure Vulnerability allows an authorized attacker to disclose information over a network due to a relative path traversal issue. This vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Defenders managing SharePoint Server installations should verify affected versions and apply patches to prevent potential exploitation and data breaches. The vulnerability has a medium severity and is being actively monitored by defenders.

Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-10-08
Advisory published
2026-08-11
Advisory updated
2026-10-08

Who should care

Defenders managing SharePoint Server installations, particularly those using Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition.

Why it matters

CVE-2026-62837 is a medium-severity vulnerability in Microsoft SharePoint Server that allows an authorized attacker to disclose information over a network. Defenders managing SharePoint Server installations should verify affected versions, apply patches, and monitor for unauthorized access attempts to prevent potential exploitation and data breaches.

  • Verify affected SharePoint Server versions to assess exposure
  • Apply patches to prevent information disclosure
  • Monitor for unauthorized access attempts to detect potential exploitation
  • Review and update incident response plans to address potential data breaches

Technical summary

A relative path traversal vulnerability in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. The vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Defenders should prioritize verifying affected SharePoint Server versions and applying vendor patches to prevent potential exploitation and data breaches.

Defensive priority

Defenders should prioritize verifying affected SharePoint Server versions and applying vendor patches.

Recommended defensive actions

  • Verify affected SharePoint Server versions
  • Apply vendor patches
  • Monitor for unauthorized access attempts

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but vendor advisory details are limited. The vulnerability was disclosed on 2026-08-11 and has not been modified since then. Defenders should verify the affected SharePoint Server versions and apply vendor patches to prevent information disclosure. The CVE Program record and NVD entry provide source-provided CVE metadata and official vulnerability assessment. Additional information may be available from vendor advisori

Sources and references

Verified primary and authoritative sources

  • CVE-2026-62837 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-62837

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-62837 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62837

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.