🟠 High | Source: Microsoft Security Response Center
CVE-2026-62837 is a path traversal vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to access files or data they should not be able to reach across a network. Because it requires only valid credentials rather than administrative access, the risk surface is broad in organisations where SharePoint is widely used. It was patched by Microsoft and organisations should apply the relevant update promptly.
Security Architect’s Take: Prioritise applying Microsoft’s patch for this CVE across all SharePoint Server instances, paying particular attention to internet-facing or hybrid deployments. In the interim, review SharePoint access controls and audit logs for unusual file-path requests that may indicate opportunistic exploitation.
Original advisory: CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability