Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEexploitVulnerability

CVE-2026-58644: CISA Adds SharePoint RCE Zero-Day to KEV Catalog

By ogwatermelon
July 18, 2026 4 Min Read
0
July 18, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. This critical Microsoft SharePoint Server flaw carries a CVSS score of 9.8 and allows an attacker authenticated as at least a Site Owner to execute arbitrary code remotely through deserialization of untrusted data. Federal agencies must patch by July 19, 2026. Consequently, all organizations running on-premises SharePoint Server should treat this as an urgent priority.

What Happened: CISA Adds SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog

CVE-2026-58644 is a critical deserialization of untrusted data vulnerability in Microsoft SharePoint Server. On July 16, 2026, CISA confirmed active exploitation and added the flaw to its KEV catalog. This move forces Federal Civilian Executive Branch (FCEB) agencies to apply patches within three days. Moreover, CISA strongly encourages all organizations to prioritize remediation regardless of federal mandate status.

Microsoft originally released patches for this vulnerability as part of its July 14, 2026 Patch Tuesday updates. However, the company subsequently revised its advisory to confirm that attackers had exploited the flaw in the wild before fixes became available. Therefore, CVE-2026-58644 qualifies as a true zero-day that transitioned to a known exploited vulnerability within two days of patching.

The affected product versions include Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Additionally, CISA warned that multiple SharePoint Server vulnerabilities are under active exploitation, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. Threat actors use these flaws to gain unauthorized access, steal IIS machine keys, and deploy malware on compromised servers.

Technical Details of the SharePoint Server Deserialization Vulnerability

CVE-2026-58644 stems from insecure deserialization of untrusted data within SharePoint Server. An attacker authenticated as at least a Site Owner can write arbitrary code and execute it remotely on the server. Microsoft confirmed that the vulnerability is remotely exploitable over the internet. Furthermore, the attack complexity is low because the attacker does not need significant prior knowledge of the target system.

Microsoft also noted that the attacker can achieve repeatable success with the same payload against the vulnerable component. This reliability makes the vulnerability especially attractive to threat actors. Post-exploitation activities observed in the wild include stealing Internet Information Services (IIS) machine keys and using deserialization techniques to gain persistence and deploy additional malware.

Attack Requirements and Affected Versions

  • Authentication level: Site Owner or higher
  • Attack vector: Network-based, remotely exploitable over the internet
  • Attack complexity: Low
  • Repeatability: High — the same payload succeeds consistently
  • Post-exploitation: IIS machine key theft, deserialization persistence, malware deployment

Product Scope

  • Microsoft SharePoint Server Subscription Edition
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Enterprise Server 2016

Business and Operational Impact

Organizations running on-premises SharePoint Server face severe consequences if this vulnerability remains unpatched. SharePoint Server is a central collaboration platform that houses sensitive documents, workflows, and business data. A successful remote code execution attack can lead to full server compromise.

  • Data exposure: Attackers can access, exfiltrate, or destroy documents stored in SharePoint libraries and sites.
  • Service disruption: Compromised servers may suffer outages, data corruption, or ransomware deployment.
  • Credential theft: IIS machine key harvesting enables attackers to forge authentication tokens and move laterally.
  • Persistence: Deserialization-based backdoors can survive routine maintenance and evade detection.
  • Compliance risk: Unpatched KEV vulnerabilities may trigger regulatory scrutiny, cyber insurance challenges, or contractual penalties.

Moreover, SharePoint Server 2016 and 2019 both reached end of extended support on July 14, 2026. Organizations still running these versions must migrate or upgrade because neither version offers a paid Extended Security Updates program. Consequently, the July Patch Tuesday fixes may be the last security updates these versions ever receive.

Mitigation and Recommendations

Immediate Actions for Defenders

  1. Patch immediately. Apply the July 14, 2026 Microsoft security updates for SharePoint Server. Verify successful installation before assuming protection.
  2. Enable AMSI integration. Turn on Antimalware Scan Interface for every SharePoint web application. Set Request Body Scan mode to Full for maximum detection coverage.
  3. Scan for compromise. Check logs and file systems for intrusion artifacts, machine key harvesting tools, and unauthorized web shells before rotating IIS machine keys.
  4. Restrict network exposure. Do not expose SharePoint Servers directly to the internet. Block external access to SharePoint Central Administration and restrict farm and database communications to required systems only.
  5. Review permissions. Audit Site Owner and Site Member assignments. Remove unnecessary privileges that could expand an attacker’s foothold.

Additional Guidance

Organizations should also establish tailored logging mechanisms to detect and monitor exploitation activities. For example, monitor SharePoint web request logs for unusual deserialization payloads or unexpected process execution. Additionally, review Microsoft’s SharePoint Server security-hardening guidance for role-specific ports, services, and Web.config settings. Furthermore, shorten patching cycles when possible to reduce the window between disclosure and remediation.

Bottom line: CVE-2026-58644 is actively exploited and carries a 9.8 CVSS score. Patch on-premises SharePoint Server immediately. Enable AMSI Full Mode, audit permissions, and scan for compromise before rotating IIS machine keys. If you run SharePoint 2016 or 2019, start migration planning today because extended support has ended.

Incident Summary

CVE ID / Incident: CVE-2026-58644
Affected Systems: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016
Disclosure Date: July 14, 2026 (patched); July 16, 2026 (CISA KEV addition)
Patch Status: Available — patches released July 14, 2026

References

  1. CISA, “CISA Adds Three Known Exploited Vulnerabilities to Catalog,” July 16, 2026, https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog, accessed July 18, 2026.
  2. The Hacker News, “CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV,” July 17, 2026, https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html, accessed July 18, 2026.
  3. Microsoft Security Response Center, “CVE-2026-58644,” July 2026, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644, accessed July 18, 2026.
  4. CISA, “CISA Urges SharePoint Hardening After New Exploitations,” July 14, 2026, https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations, accessed July 18, 2026.

Tags:

CVEExploitVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

OkoBot Malware Framework Deploys 20+ Payloads to Steal Crypto and Credentials

Next

OpenSSL HollowByte DoS Flaw: 11-Byte Payload Freezes Server Memory

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.