Somewhere, a federal IT admin is currently rediscovering the concept of a weekend deadline. Microsoft SharePoint has a new critical flaw, it's already being exploited in the wild, and CISA just handed out homework due today.
A 9.8-Rated Hole in Everyone's Intranet
CVE-2026-58644 is a critical deserialization vulnerability in on-premises SharePoint Server — Subscription Edition, 2019, and 2016 are all affected — carrying a CVSS score of 9.8 out of 10. That means an unauthenticated attacker can execute arbitrary code on your server without so much as guessing a password.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 16, confirming it was weaponized as a zero-day before a fix was even available. Attackers have reportedly been using it to steal IIS machine keys and deploy malware for long-term persistence — the kind of foothold that outlives a simple patch.
The Clock CISA Set Is Already Ringing
Federal civilian agencies were given until today, July 19, to apply fixes under CISA's directive — a remarkably tight turnaround that signals just how seriously the agency is treating active exploitation. For everyone else running on-prem SharePoint, "eventually" is not an acceptable patch cadence here.
The bigger pattern worth noticing: this is yet another on-prem SharePoint RCE joining a growing club of similar flaws over the past year. If your organization's answer to "why haven't we moved off on-prem SharePoint" is inertia, this is the universe's latest reminder that inertia has a CVSS score too.
Patch it, rotate those machine keys, and maybe finally have the cloud migration conversation you've been avoiding.
Source: The Hacker News