CVE-2026-62837Patch(microsoft / sharepoint_server)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft sharepoint_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-11: 1Mentions · 2026-08-15: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-15: 1Technical Details · 2026-08-15: 108-1108-15
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-111
Patch1
2026-08-151
Disclosure1
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-62837 - Path traversal info disclosure in Microsoft Office SharePoint. CVSS 6.5. Patch under review. Monitor advisories and restrict access. #CVE #Microsoft #infosec https://www.valtersit.com/cve/CVE-2026-62837 #CVE #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta

    Post summary

    The post announces a new path‑traversal info disclosure in Microsoft Office SharePoint (CVE‑2026‑62837, CVSS 6.5) with a patch currently under review and advises limiting access.

    0000072
    1.0K followersView on X
  • Windows Forum@windowsforum
    Patch

    🛡️ CVE-2026-62837 exposes information in on-prem SharePoint. Patch every farm and verify the fixed build—because “we have SharePoint” is not a security strategy, and SharePoint Online settings won’t help. https://windowsforum.com/security-alerts.84/cve-2026-62837-patch-sharepoint-server-information-disclosure.442481/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #SecurityUpdates #PatchManagement #SharepointServer https://t.co/ao3dd2uufS

    Post summary

    The post alerts users to CVE‑2026‑62837 exposing information on on‑prem SharePoint and urges patching, but provides no PoC, exploit, or detailed technical data.

    0000045
    1.3K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more