Your SharePoint Server Has a 9.8-Out-of-10 Problem

Your SharePoint Server Has a 9.8-Out-of-10 Problem

Somewhere, a federal IT admin is currently rediscovering the concept of a weekend deadline. Microsoft SharePoint has a new critical flaw, it's already being exploited in the wild, and CISA just handed out homework due today.

A 9.8-Rated Hole in Everyone's Intranet

CVE-2026-58644 is a critical deserialization vulnerability in on-premises SharePoint Server — Subscription Edition, 2019, and 2016 are all affected — carrying a CVSS score of 9.8 out of 10. That means an unauthenticated attacker can execute arbitrary code on your server without so much as guessing a password.

CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 16, confirming it was weaponized as a zero-day before a fix was even available. Attackers have reportedly been using it to steal IIS machine keys and deploy malware for long-term persistence — the kind of foothold that outlives a simple patch.

The Clock CISA Set Is Already Ringing

Federal civilian agencies were given until today, July 19, to apply fixes under CISA's directive — a remarkably tight turnaround that signals just how seriously the agency is treating active exploitation. For everyone else running on-prem SharePoint, "eventually" is not an acceptable patch cadence here.

The bigger pattern worth noticing: this is yet another on-prem SharePoint RCE joining a growing club of similar flaws over the past year. If your organization's answer to "why haven't we moved off on-prem SharePoint" is inertia, this is the universe's latest reminder that inertia has a CVSS score too.

Patch it, rotate those machine keys, and maybe finally have the cloud migration conversation you've been avoiding.

Curious how solid your own stack would hold up? Get in touch and we'll take a look.

Source: The Hacker News