UPDATE: Critical Microsoft SharePoint Server Zero-Days Under Active Exploitation

❓What:
CISA added critical zero-day vulnerabilities targeting Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog
CVE-2026-58644 is a deserialization flaw in SharePoint Server (Subscription Edition, 2019, and 2016) that allows remote, authenticated attackers to execute arbitrary code, gain persistence — historically through IIS machine key theft — and establish footholds in enterprise environments
CVE-2026-50522 is a critical SharePoint Server deserialization RCE vulnerability with a CVSS score of 9.8; public proof-of-concept exploit code became available shortly after Microsoft's July 2026 emergency patches, contributing to rapid and widespread exploitation
CISA added CVE-2026-58644 to the KEV catalog on July 16, 2026, with a remediation deadline of July 19, 2026 for federal agencies
SharePoint Online is not affected — this is on-premises only
⚠️ Impact:
Affected sectors include U.S. government, enterprise, financial, healthcare, and any organization operating on-premises SharePoint Server
The zero-day window was extremely short — organizations had at most 5 days from disclosure to mandatory patching
Risk includes system takeover, data exfiltration, lateral movement, and deployment of ransomware or spyware
Exploitation of CVE-2026-50522 has been observed globally against on-premises SharePoint Server deployments
💡 Recommendations:
Patch to the latest cumulative updates immediately: Subscription Edition KB5002882, 2019 KB5002883/KB5002885, 2016 KB5002891/KB5002892
If patching isn't immediately possible, remove public internet exposure via network segmentation, firewall rules, or take servers offline
Rotate ASP.NET machine keys and restart IIS after patching to invalidate any stolen credentials or abused sessions, and change SharePoint/IIS service account passwords
Enable AMSI Full Mode and Defender AV on all SharePoint servers; enforce MFA and least-privilege access on admin interfaces
Decommission or isolate end-of-life SharePoint installations from internet exposure long-term
Read the full story HERE
