top of page

Security Bulletin

Public·4 members

Jake Geier
Jake Geier

UPDATE: Critical Microsoft SharePoint Server Zero-Days Under Active Exploitation



What:

  • CISA added critical zero-day vulnerabilities targeting Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog

  • CVE-2026-58644 is a deserialization flaw in SharePoint Server (Subscription Edition, 2019, and 2016) that allows remote, authenticated attackers to execute arbitrary code, gain persistence — historically through IIS machine key theft — and establish footholds in enterprise environments

  • CVE-2026-50522 is a critical SharePoint Server deserialization RCE vulnerability with a CVSS score of 9.8; public proof-of-concept exploit code became available shortly after Microsoft's July 2026 emergency patches, contributing to rapid and widespread exploitation

  • CISA added CVE-2026-58644 to the KEV catalog on July 16, 2026, with a remediation deadline of July 19, 2026 for federal agencies

  • SharePoint Online is not affected — this is on-premises only


⚠️ Impact:

  • Affected sectors include U.S. government, enterprise, financial, healthcare, and any organization operating on-premises SharePoint Server

  • The zero-day window was extremely short — organizations had at most 5 days from disclosure to mandatory patching

  • Risk includes system takeover, data exfiltration, lateral movement, and deployment of ransomware or spyware

  • Exploitation of CVE-2026-50522 has been observed globally against on-premises SharePoint Server deployments


💡 Recommendations:

  • Patch to the latest cumulative updates immediately: Subscription Edition KB5002882, 2019 KB5002883/KB5002885, 2016 KB5002891/KB5002892

  • If patching isn't immediately possible, remove public internet exposure via network segmentation, firewall rules, or take servers offline

  • Rotate ASP.NET machine keys and restart IIS after patching to invalidate any stolen credentials or abused sessions, and change SharePoint/IIS service account passwords

  • Enable AMSI Full Mode and Defender AV on all SharePoint servers; enforce MFA and least-privilege access on admin interfaces

  • Decommission or isolate end-of-life SharePoint installations from internet exposure long-term

Read the full story HERE

13 Views
bottom of page