The Deadline Is Today: What You Need to Know Right Now
If your organization runs on-premises Microsoft SharePoint Server, this is the story to read before anything else this week. A critical remote code execution flaw, tracked as CVE-2026-58644, is being actively exploited in the wild, and the US Cybersecurity and Infrastructure Security Agency (CISA) has set July 19, 2026 as the deadline for federal civilian agencies to patch it. Private-sector organizations aren't bound by that deadline legally, but security teams are treating it as the practical one too.
What CVE-2026-58644 Actually Is
| π Security Detail | π Information |
|---|---|
| β οΈ CVSS Score | 9.8 / 10 (Critical) β One of the highest severity ratings under the CVSS framework. |
| π‘οΈ Vulnerability Type | Deserialization of untrusted data, enabling malicious payload execution. |
| π₯ Potential Impact | Remote Code Execution (RCE), allowing attackers to execute arbitrary code on vulnerable servers. |
| π₯οΈ Affected Products | Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 (on-premises deployments only). |
| π Security Patch Released | July 14, 2026 as part of Microsoft's Patch Tuesday updates. |
| π¨ Added to CISA KEV | July 16, 2026, indicating confirmed exploitation in the wild. |
| β³ Federal Patch Deadline | July 19, 2026 for affected U.S. federal agencies. |
According to Microsoft's own advisory, an attacker authenticated as at least a Site Owner can write and execute arbitrary code directly on the SharePoint Server over a network connection. Two factors make it especially dangerous: the attacker doesn't need deep prior knowledge of the target system, and successful exploits can be repeated reliably against other vulnerable instances β meaning automated, large-scale scanning and exploitation is straightforward once a working payload exists.
It’s Not Just One Vulnerability
CVE-2026-58644 is part of a cluster of actively exploited SharePoint flaws CISA is tracking together: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. Collectively, these enable remote code execution and a range of post-exploitation techniques β notably, attackers have been observed stealing Internet Information Services (IIS) machine keys and performing further deserialization attacks to establish persistence and deploy malware once inside.
Why On-Premises SharePoint Is Such a High-Value Target
On-premises SharePoint servers frequently store internal documents, business records, credentials, workflow data and integration secrets β making a successful compromise far more damaging than a typical single-application breach, since it often opens a path into everything the server was trusted to hold or connect to.
How This Fits Into a Record Patch Tuesday
The July 2026 Patch Tuesday release was unusually large, addressing more than 600 CVEs in total. Buried in that volume were two other vulnerabilities already being exploited in the wild: CVE-2026-56164, an unauthenticated elevation-of-privilege flaw in on-premises SharePoint, and CVE-2026-56155, a local privilege escalation in Active Directory Federation Services (AD FS) that Microsoft's own incident response teams discovered during live intrusions. CISA added CVE-2026-56155 to its KEV catalog on July 14 with a July 28 remediation deadline β a reminder that this SharePoint issue isn't an isolated event but part of a broader wave of identity- and document-infrastructure attacks this month.
Industry Impact
Security teams are increasingly having to re-triage vulnerability priorities within hours rather than on a weekly cadence, as CISA added six KEV entries in just two days during this cycle. Compliance and security researchers are describing the July 2026 Patch Tuesday as a "compliance event, not just a patching one" β meaning organizations subject to regulatory frameworks referencing the KEV catalog now face documentation and audit obligations tied directly to how quickly they respond, not just whether they eventually do.
What You Should Do Right Now
- Apply the July 2026 Patch Tuesday updates immediately to all on-premises SharePoint Server Subscription Edition, 2019, and 2016 instances.
- Rotate IIS machine keys on affected servers, since attackers have specifically been observed stealing these to maintain persistence even after patching.
- Review authentication logs for unusual Site Owner-level activity predating the patch, since exploitation was confirmed before a fix was available.
- Prioritize internet-facing SharePoint instances first, given Microsoft's confirmation that the flaw is remotely exploitable with low attack complexity.
- Check AD FS servers separately for CVE-2026-56155 given its use as a second-stage privilege escalation vector after initial access.
Timeline
- July 14, 2026: Microsoft ships its July Patch Tuesday update, addressing over 600 CVEs including CVE-2026-58644.
- July 15, 2026: Microsoft updates its advisory to confirm CVE-2026-58644 was exploited in the wild as a zero-day before the patch existed.
- July 16, 2026: CISA adds CVE-2026-58644 to its Known Exploited Vulnerabilities catalog.
- July 19, 2026: Federal Civilian Executive Branch agencies' patch deadline.
Future Outlook
Given how quickly this cluster of SharePoint flaws moved from patch release to confirmed exploitation, expect continued scanning activity against unpatched on-premises instances well past the federal deadline β private organizations that delay remediation should assume they remain an active target. Security researchers are also watching whether the same threat actors exploiting CVE-2026-58644 pivot toward the related AD FS flaw as a follow-on technique, given how directly it extends the value of an initial SharePoint compromise.
Frequently Asked Questions
What is CVE-2026-58644?
A critical (CVSS 9.8) deserialization vulnerability in on-premises Microsoft SharePoint Server that allows an authenticated attacker to remotely execute arbitrary code.
Is CVE-2026-58644 being actively exploited?
Yes β Microsoft confirmed exploitation in the wild before a patch was available, and CISA added it to its Known Exploited Vulnerabilities catalog on July 16, 2026.
What is the patch deadline?
CISA has directed federal civilian agencies to patch by July 19, 2026; private organizations are strongly urged to treat this as their deadline too.
Does this affect SharePoint Online or only on-premises servers?
It affects on-premises SharePoint Server Subscription Edition, 2019, and 2016 β not Microsoft's cloud-hosted SharePoint Online.
What should I do if I can’t patch immediately?
Prioritize isolating internet-facing SharePoint instances, monitor for unusual Site Owner activity, and rotate IIS machine keys as an interim mitigation.
Are there other SharePoint vulnerabilities being exploited right now?
Yes β CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are also being actively exploited alongside CVE-2026-58644.
Why is this vulnerability considered especially dangerous?
Because it's remotely exploitable with low attack complexity, doesn't require deep knowledge of the target system, and can be reliably repeated across multiple vulnerable servers.
Key Takeaways
- CVE-2026-58644 is a critical, actively exploited SharePoint remote code execution flaw with a July 19, 2026 federal patch deadline.
- It's one of at least four SharePoint vulnerabilities under active exploitation this month, part of a record 600+ CVE Patch Tuesday.
- Attackers are specifically stealing IIS machine keys, meaning patching alone may not fully remediate an already-compromised server.
- A related AD FS privilege escalation flaw (CVE-2026-56155) adds further urgency given its use as a post-compromise pivot point.
References
- CISA
- The Hacker News
- SecurityWeek
- ComplianceHub.Wiki






