Your SharePoint Server Has a 9.8-Out-of-10 Problem

Your SharePoint Server Has a 9.8-Out-of-10 Problem

Somewhere, a federal IT admin is currently rediscovering the concept of a weekend deadline. Microsoft SharePoint has a new critical flaw, it's already being exploited in the wild, and CISA just handed out homework due today.

A 9.8-Rated Hole in Everyone's Intranet

CVE-2026-58644 is a critical deserialization vulnerability in on-premises SharePoint Server — Subscription Edition, 2019, and 2016 are all affected — carrying a CVSS score of 9.8 out of 10. That means an unauthenticated attacker can execute arbitrary code on your server without so much as guessing a password.

CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 16, confirming it was weaponized as a zero-day before a fix was even available. Attackers have reportedly been using it to steal IIS machine keys and deploy malware for long-term persistence — the kind of foothold that outlives a simple patch.

The Clock CISA Set Is Already Ringing

Federal civilian agencies were given until today, July 19, to apply fixes under CISA's directive — a remarkably tight turnaround that signals just how seriously the agency is treating active exploitation. For everyone else running on-prem SharePoint, "eventually" is not an acceptable patch cadence here.

The bigger pattern worth noticing: this is yet another on-prem SharePoint RCE joining a growing club of similar flaws over the past year. If your organization's answer to "why haven't we moved off on-prem SharePoint" is inertia, this is the universe's latest reminder that inertia has a CVSS score too.

Patch it, rotate those machine keys, and maybe finally have the cloud migration conversation you've been avoiding.

Source: The Hacker News