轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000009
[內容說明]
Microsoft SharePoint Server 是一款企業級協作平台,提供文件管理與團隊協作等功能,是企業資訊整合的核心平台。近期微軟發布重大資安公告(CVE-2026-58644,CVSS:9.8 和 CVE-2026-55040,CVSS:9.1),CVE-2026-58644為不受信任資料之反序列化漏洞,允許未經授權的攻擊者透過網路執行任意程式碼;CVE-2026-55040為弱身份驗證漏洞,允許未經授權的攻擊者透過網路繞過安全功能。
[影響平台]
Microsoft SharePoint Server Subscription Edition、 Microsoft SharePoint Server 2019、 Microsoft SharePoint Enterprise Server 2016
[建議措施]
根據官方網站釋出解決方式進行修補:
【CVE-2026-58644】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
【CVE-2026-55040】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
Forwarded Taiwan Computer Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000009
[Description]
Microsoft SharePoint Server is an enterprise-level collaboration platform that provides functions such as document management and team collaboration, and serves as a core platform for enterprise information integration. Recently, Microsoft released a critical security advisory (CVE-2026-58644, CVSS: 9.8 and CVE-2026-55040, CVSS: 9.1). CVE-2026-58644 is a deserialization of untrusted data vulnerability, allowing unauthorized attackers to execute arbitrary code over the network; CVE-2026-55040 is a weak authentication vulnerability, allowing unauthorized attackers to bypass security features over the network.
[Affected Platforms]
Microsoft SharePoint Server Subscription Edition、 Microsoft SharePoint Server 2019、 Microsoft SharePoint Enterprise Server 2016
[Recommended Actions]
Apply patches according to the solutions provided on the official website:
【CVE-2026-58644】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
【CVE-2026-55040】 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
【資安漏洞預警】Microsoft 旗下SharePoint Server 存在2個重大資安漏洞
[Security Vulnerability Alert] Microsoft's SharePoint Server has two major security vulnerabilities.
公告類別:行政公告
發佈日期:2026/07/23 至 2027/01/23
點閱數:122
相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
返回列表



