Critical SharePoint Flaw Being Actively Exploited

What has happened

Microsoft’s July Patch Tuesday – the second Tuesday of every month when Microsoft releases its scheduled batch of security fixes – brought an unusually urgent warning on 14 July 2026. Alongside a record-breaking set of updates, Microsoft confirmed that a critical vulnerability in on-premises SharePoint Server was already being exploited by attackers before many organisations had a chance to apply the fix.

The vulnerability is tracked as CVE-2026-58644 and carries a severity score of 9.8 out of 10 – placing it in the highest possible risk band. It affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. SharePoint Online – the cloud-hosted version included in Microsoft 365 – is not affected.

The flaw is caused by the way SharePoint handles serialised data: structured information sent to the server. An attacker can send specially crafted requests to an unpatched server and, without needing a username or password, execute malicious code with the privileges of the SharePoint application. Once inside, attackers have been observed stealing encryption keys used to protect the server, establishing persistent footholds, and deploying additional malware.

CISA – the US Cybersecurity and Infrastructure Security Agency, whose Known Exploited Vulnerabilities catalogue is the closest thing to an official “patch this now” list – added CVE-2026-58644 on 16 July 2026, just two days after the patch was released. That fast-track listing confirms this is not a theoretical risk; exploitation is happening in the real world.

Why this matters to your business

If your business runs an on-premises SharePoint Server – whether for document management, intranets, workflow automation, or team collaboration – you are directly in the firing line. The barrier for attackers is unusually low: no credentials are required. A device connected to the internet, or a malicious actor already inside your network, can attempt to exploit this without ever logging in.

There is an added complication specific to this flaw. SharePoint Server 2016 reached its end of extended support in July 2026, and SharePoint Server 2019 is approaching the same milestone. End of support means Microsoft is no longer obligated to issue security patches for those versions. In this case Microsoft did issue a patch, because active exploitation made it necessary – but businesses on these versions cannot rely on that happening again. Running end-of-life server software while exploitation is underway is a position that demands immediate action.

Businesses running SharePoint Online as part of a Microsoft 365 subscription have nothing to action here. Microsoft manages and patches the cloud service automatically.

What we have done and would suggest

For our managed clients running the affected SharePoint versions, we are actively verifying patch status and applying the July 2026 cumulative updates. The specific updates Microsoft has released are:

  • SharePoint Server Subscription Edition – KB5002882
  • SharePoint Server 2019 – KB5002883
  • SharePoint Server 2016 – KB5002891

If you use SharePoint Workflow Manager with Subscription Edition, Microsoft requires the Workflow Manager update to be applied first, before KB5002882.

If you manage your own SharePoint environment and have not yet applied the July Patch Tuesday updates, this should be your immediate priority. Microsoft’s own guidance is clear: treat this as a critical, act-now update.

What to check and what to do next

1. Identify your SharePoint version. In SharePoint Server, open Central Administration and note the build number. Compare it against the patched build versions listed in the relevant KB article to confirm whether the fix is in place.

2. Apply the July 2026 cumulative update. Follow the standard SharePoint patching sequence: apply the update to your database server first, then your application servers, then run the SharePoint Products Configuration Wizard on each server in the farm. Do not skip the configuration wizard step – the patch will not fully take effect without it.

3. Review your server logs for unusual activity. If your SharePoint server was publicly accessible before patching, it is worth checking IIS logs for unexpected request patterns, reviewing Windows event logs for new scheduled tasks or services, and checking for any changes to IIS machine keys. These are common indicators of post-exploitation activity.

4. Plan your longer-term position. If you are running SharePoint Server 2016 or 2019, this vulnerability is a reminder of the risk that comes with end-of-life software. Moving to SharePoint Online via Microsoft 365 eliminates this class of risk entirely: patches are applied automatically, and your organisation is always on the current, supported version.

If you would like help applying the emergency patch, auditing your SharePoint environment, or planning a migration to the cloud, get in touch with us. Our managed IT support service includes proactive patch management so critical updates are applied before your business is exposed. You can also read more about our approach to IT security for SMBs across the UK.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name