A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
Use CWE-20, Microsoft vendor hub and Sharepoint Enterprise Server product page to widen CVE-2019-0604 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-49706, CVE-2025-47172 and CVE-2025-47166 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.